September 02, 21:27

US officials work with CrowdStrike to disrupt malware behind crypto theft

US Officials Work with CrowdStrike to Fight Malware behind Crypto Theft

Cointelegraph

US federal authorities and CrowdStrike disrupted the Sality botnet and malware linked to cryptocurrency theft. The Justice Department announced the action in a Tuesday notice. The international effort involved officials from Bulgaria, Hungary and Romania. The effort also involved the Shadowserver Foundation. US officials said Sality had installed malware on compromised devices since 2003. CrowdStrike said entities behind Sality used the EggJagger clipjacking tool during the previous eight years. The tool monitored clipboard data for cryptocurrency wallet addresses. The tool replaced copied addresses with addresses controlled by the operator. CrowdStrike said the entities stole at least 12.1 million rubles in cryptocurrency. CrowdStrike valued the theft at about $150,000. CrowdStrike said the never-spent digital assets peaked at about $1.5 million in January 2025. CrowdStrike said authorities' efforts caused the criminals to lose the ability to communicate with infected machines. US officials and CrowdStrike said Sality was used to steal cryptocurrency. About 15,000 infected computers formed part of a peer-to-peer botnet. The botnet checked whether its systems were online every 40 minutes.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.