BlocktoBlockto
US Authorities and CrowdStrike Disrupt Long-Running Crypto Theft Malware
NEWS

Photo: Illustrative

US Authorities and CrowdStrike Disrupt Long-Running Crypto Theft Malware

Federal law enforcement officials, working alongside cybersecurity firm CrowdStrike, have disrupted a global malware network responsible for stealing cryptocurrency from unsuspecting victims over nearly two decades. The Justice Department confirmed the takedown of the Sality botnet in a joint operation involving authorities from Bulgaria, Hungary and Romania, along with private cybersecurity partners CrowdStrike and the Shadowserver Foundation.

Laurisa
By Laurisa

Junior Author · September 3, 2026

2 min
Key takeaways
Federal law enforcement officials, working alongside cybersecurity firm CrowdStrike, have disrupted a global malware network responsible for stealing cryptocurrency from unsuspecting victims over nearly two decades.
The Justice Department confirmed the takedown of the Sality botnet in a joint operation involving authorities from Bulgaria, Hungary and Romania, along with private cybersecurity partners CrowdStrike and the Shadowserver Foundation.
Officials say the malware has been infecting devices since 2003, enabling both cyberattacks and crypto theft over the years.

Federal law enforcement officials, working alongside cybersecurity firm CrowdStrike, have disrupted a global malware network responsible for stealing cryptocurrency from unsuspecting victims over nearly two decades. The Justice Department confirmed the takedown of the Sality botnet in a joint operation involving authorities from Bulgaria, Hungary and Romania, along with private cybersecurity partners CrowdStrike and the Shadowserver Foundation.

Officials say the malware has been infecting devices since 2003, enabling both cyberattacks and crypto theft over the years.

How the Malware Stole Crypto Payments

CrowdStrike revealed that over the past eight years, operators behind Sality used a clipboard-hijacking tool called EggJagger to silently swap copied cryptocurrency wallet addresses with ones controlled by the attackers.

This meant that whenever a victim attempted to send Bitcoin or Ethereum, the funds were secretly rerouted to the criminals instead. The scheme resulted in roughly $150,000 worth of stolen crypto, with unspent holdings once valued at approximately $1.5 million.

The botnet had infected close to 15,000 computers worldwide, which regularly checked in with a peer to peer network. Following the coordinated crackdown, authorities say the operators have lost their ability to control the infected machines.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Laurisa
Laurisa

Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.