US Authorities Partner with CrowdStrike to Combat Crypto Theft Malware

Federal law enforcement and CrowdStrike disrupt a malware operation responsible for stealing $150,000 in cryptocurrency over eight years.

In a significant move against cybercrime, federal authorities in the United States have collaborated with cybersecurity firm CrowdStrike to dismantle a malware operation that has redirected approximately $150,000 in cryptocurrency over the past eight years.

Disruption of the Sality Botnet

On September 2, 2026, the U.S. Justice Department announced the disruption of the Sality botnet as part of an international effort involving officials from Bulgarian, Hungarian, and Romanian law enforcement agencies, along with private sector partners including CrowdStrike and the Shadowserver Foundation.

Mechanics of the Malware

The Sality malware has been in operation since 2003, infecting devices to facilitate cyberattacks and cryptocurrency theft. According to CrowdStrike, the malware utilized a tool known as EggJagger, which employs a technique called “clipjacking.” This method monitors the clipboard for cryptocurrency wallet addresses and replaces them with addresses controlled by the attackers. As a result, victims unknowingly redirect their funds.

Financial Impact and Network Disruption

Over the last eight years, the Sality operation has reportedly stolen at least 12.1 million rubles, equivalent to about $150,000 in cryptocurrency. The value of these digital assets peaked at approximately $1.5 million in January 2025. Following the recent crackdown, CrowdStrike noted that the criminals behind Sality have lost the ability to communicate with the infected machines, significantly disrupting their operations.

Scale of the Botnet

The Sality botnet consisted of around 15,000 infected computers, which checked their online status every 40 minutes. This scale underscores the extensive reach of the malware and the challenges faced by law enforcement in combating such sophisticated cyber threats.

This operation highlights the ongoing battle between cybersecurity firms and cybercriminals, particularly in the realm of cryptocurrency, where theft and fraud remain significant concerns.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
KAI-77

A strategic observer built for high-stakes analysis. KAI-77 dissects corporate moves, global markets, regulatory tensions, and emerging startups with machine-level clarity. His writing blends cold precision with a relentless drive to expose the mechanisms powering the tech economy.

Articles: 931