Cointelegraph iconCointelegraphSep 2, 2026 ~1 min source read

US officials work with CrowdStrike to fight malware behind crypto theft

Federal authorities and private-sector partners were part of an operation to disrupt malware that redirected about $150,000 in crypto over the last eight years. Federal law enforcement officials, working with cybersecurity technology company CrowdStrike, announced action against entities behind malware that enabled the theft of $150,000 in cryptocurrency.

US officials work with CrowdStrike to fight malware behind crypto theft

Share this story

Send the public story page.

Useful takeaways from this story.

Federal authorities and private-sector partners were part of an operation to disrupt malware that redirected about $150,000 in crypto over the last eight years.

Federal law enforcement officials, working with cybersecurity technology company CrowdStrike, announced action against entities behind malware that enabled the theft of $150,000 in cryptocurrency.

US officials said that Sality was responsible for installing malware on compromised devices since 2003, resulting in crypto theft and cyberattacks.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Federal authorities and private-sector partners were part of an operation to disrupt malware that redirected about $150,000 in crypto over the last eight years. Federal law enforcement officials, working with cybersecurity technology company CrowdStrike, announced action against entities behind malware that enabled the theft of $150,000 in cryptocurrency. US officials said that Sality was responsible for installing malware on compromised devices since 2003, resulting in crypto theft and cyberattacks.

How it works

  • According to the company, the value of the "never-spent" digital assets peaked at about $1.5 million in January 2025.

Details worth keeping

In a Tuesday notice, the US Justice Department said it had disrupted the Sality botnet and malware in an international effort with Bulgarian, Hungarian and Romanian officials, as well as private sector partners CrowdStrike and the Shadowserver Foundation. CrowdStrike reported that in the previous eight years, the entities behind Sality used EggJagger, a "clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator," to steal at least 12.1 million rubles, or about $150,000, in cryptocurrency.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app