US Officials Shut Down Sality Botnet Behind Crypto Heists
US authorities have teamed up with cybersecurity firm CrowdStrike to take down malware that enabled crypto theft. The malware, known as Sality, has been around since 2003 and has installed itself on compromised devices, resulting in cyberattacks and the theft of cryptocurrency.
CrowdStrike reported that entities behind Sality used a 'clipjacking tool' called EggJagger to steal at least $150,000 in cryptocurrency over the past eight years. The tool works by monitoring the clipboard for Bitcoin or Ethereum wallet addresses and replacing them with addresses controlled by the operator.
When a victim copies a cryptocurrency address to make a payment, the funds are redirected to the attacker's address instead of reaching the intended recipient. According to CrowdStrike, Sality was used to steal crypto, while about 15,000 infected computers formed part of a peer-to-peer botnet that checked whether its systems were online every 40 minutes.
As a result of authorities' efforts to disrupt the network, the entities behind Sality 'lost the ability to communicate with infected machines.' The value of the stolen cryptocurrency peaked at around $1.5 million in January 2025.