US Officials Dismantle Malware Behind Crypto Theft with CrowdStrike Help
US federal law enforcement officials have collaborated with cybersecurity firm CrowdStrike to take down entities behind malware responsible for cryptocurrency theft. The malware, known as Sality, has been infecting devices since 2003 and was used in a botnet that checked its systems every 40 minutes.
CrowdStrike reported that the entities behind Sality stole at least $150,000 in cryptocurrency using a 'clipjacking tool' called EggJagger. This tool monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator.
When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected to the attackers' wallets. The value of the digital assets stolen using this technique peaked at around $1.5 million in January 2025.