International operation targets the Sality botnet
An operation was carried out against the Sality botnet and related malware, which were reportedly used for crypto theft in the U.S. In a statement released on Tuesday, the U.S. Department of Justice said the network’s operations were disrupted with support from authorities in Bulgaria, Hungary and Romania, as well as private-sector partners CrowdStrike and the Shadowserver Foundation.
According to officials, Sality had been used since 2003 to load malware onto compromised devices. The statement said the infrastructure was linked both to theft of crypto assets and to other cyberattacks.
Who took part in the operation?
The investigation was carried out through cooperation between public agencies and cybersecurity firms. According to the file, the targeted infrastructure relied on a botnet mechanism operating internationally and bringing infected devices together in a peer-to-peer network.
How did the malware change wallet addresses?
According to CrowdStrike, the structure behind Sality used a clipjacking tool called EggJagger over the past eight years. The tool monitored crypto wallet addresses copied to the clipboard by users and silently replaced them with addresses controlled by the attackers.
This method caused payments to be redirected to another wallet without users noticing, especially in Bitcoin and Ethereum transfers. The company said at least 12.1 million rubles, or about $150,000, in crypto assets were stolen using this method.
What do the numbers show?
CrowdStrike said the value of unspent digital assets peaked at about $1.5 million in January 2025. The data shows that address-replacement attacks that may seem small in individual amounts can grow into a significant financial total over time.
Key figures
- The number of infected devices believed to be part of the botnet was about 15,000.
- The network was reported to check whether systems were online every 40 minutes.
- The activity linked to crypto theft spans the past eight years.
What was the outcome of the intervention?
U.S. officials and CrowdStrike said that, after the operation, the people behind Sality lost the ability to communicate with infected machines. It was announced that a significant part of the infrastructure used for crypto theft through address replacement had been taken offline.
The case once again showed how malware targeting the copy-paste habit in crypto transfers can cause direct financial losses. It also highlighted the growing importance of cooperation between public authorities and the private sector in combating cross-border cybercrime.
"""
Comments (0)
No comments yet. Be the first to comment.
Write a Comment