U.S. federal law enforcement agencies join forces with CrowdStrike and international partners to combat Sality's malware ecosystem
U.S. federal law enforcement agencies, with the cooperation of cybersecurity company CrowdStrike and international partners, announced a crackdown on the Sality malware ecosystem. According to authorities, this chain of infections has lasted for more than two decades and has been used to steal cryptocurrencies and carry out cyber attacks.
The U.S. Department of Justice said in an announcement issued on Tuesday that through the joint efforts of official agencies in Bulgaria, Hungary and Romania, as well as private sector partners CrowdStrike and Shadowserver Foundation, it has successfully disrupted the Sality botnet and related malware. The Justice Department pointed out that Sality was linked to long-term hacking activities dating back to 2003, including installing malware on infected devices.
Core Points
The U.S. Department of Justice says the Sality botnet and malware infrastructure have been disrupted through coordinated international action. CrowdStrike reported that clipboard-based "cliphijacking" technology was used to replace cryptocurrency addresses with addresses controlled by attackers. According to CrowdStrike, the entity behind Sality has stolen at least 12.1 million rubles (about $150,000) in the past eight years. Authorities described a point-to-point botnet of about 15,000 infected computers that regularly checks whether targets are online. During the operation, Sality's controllers allegedly lost the ability to communicate with infected machines.
Impact of clipboard hijacking on cryptocurrency security
The most critical information in the report was how the theft was carried out. CrowdStrike said that over the past eight years, controllers have used a clipper tool called EggJagger, which monitors cryptocurrency wallet addresses on victims 'clipboard and then quietly replaces them with addresses controlled by the attacker.
In fact, this mechanism targets a common behavior of users: copying and pasting the wallet address when sending funds. According to CrowdStrike, when a victim copies a Bitcoin or Ethereum address to complete the payment, the funds are redirected to the replaced address. This type of attack is particularly damaging because it does not require the victim to sign malicious transactions or interact with fake websites. Instead, it disrupts the transaction process during address entry-which means that users who rely on clipboard copy-and-paste can be deceived even if they have never consciously interacted with malware prompts or phishing pages.
The scale and reporting impact of Operation Sality
In a report on the crackdown, CrowdStrike said that the scrapjacking method stole at least 12.1 million rubles (approximately US$150,000) of cryptocurrency during the period it described. The company also emphasized that stolen assets were "never spent," meaning that during the observation period, the seized digital funds were never subsequently used or transferred from addresses associated with the attacker.
The company further noted that the value of these "never spent" assets peaked at approximately $1.5 million in January 2025, giving an idea of what the benefits of storage could reach once the operational theft process continues to operate.
Although the stolen amounts and peak valuations in the report only reflect CrowdStrike's observations in its analysis, they help explain why disrupting botnets 'communication channels is crucial: If controllers cannot reliably control or maintain infections, their ability to trigger address replacements and collect funds is diminished.
How botnets work-and what this operation has changed
Both U.S. officials and CrowdStrike describe Sality as a point-to-point botnet. According to the company, the network contains about 15,000 infected computers and checks every 40 minutes to see if the system is online. This regular connection helps ensure that malware controllers can continue to keep track of the infection status and continue malicious operations if possible.
After authorities took action, CrowdStrike said the criminals had "lost the ability to communicate with infected machines." In botnet operations, this loss is often decisive: Even if infected devices remain temporarily, cutting off command-and-control communications reduces the malware's ability to coordinate, update, and perform its most profitable functions.
The Justice Department's announcement describes the operation as part of a broader crackdown on Sality malware and related botnet infrastructure, rather than just clearing individual infections. The key message for cryptocurrency users is that such activities can be long-term-the Justice Department says Sality has been responsible for installing malware on infected devices since 2003-so law enforcement action and technical disruption are crucial to shrinking the attacker's operating space.
What investors and users should pay attention to
This crackdown highlights how cryptocurrency theft is increasingly combining malware distribution with human workflow attacks such as clipboard hijacking. Users should view clipboard address substitutions as a real threat-especially when sending Bitcoin or Ethereum funds-and consider verifying the receiving address through out-of-band methods (e.g., checking the pasted address against a trusted source, or using verification steps in wallet software).
Looking ahead, an open question is how attackers will adapt if their ability to communicate with infected machines is limited. As the impact of the collapse of Sality's infrastructure spreads to criminal activity, readers should be concerned about subsequent malware variants, new clipboard hijacking tools, or broader changes in the way criminals maintain access to victims 'devices.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
ETH