CrowdStrike and Authorities Dismantle 8-Year Crypto-Stealing Malware
What happened: CrowdStrike, in partnership with U.
What happened: CrowdStrike, in partnership with U.S. and European law enforcement, dismantled the Sality botnet, which had been active since 2003 and stealing crypto for the last eight years via a clipboard-hijacking payload called "EggJagger." The operation isolated over 15,000 infected machines by exploiting Sality's peer-to-peer architecture. Confirmed thefts totaled at least 12.1 million rubles (~$150,000), with the attackers' crypto holdings peaking near $1.35 million in early 2025.
Why it matters: Despite its long run, Sality's financial impact was relatively modest, underscoring that persistent, low-profile malware can quietly siphon funds over years without major headlines. The takedown demonstrates the increasing effectiveness of public-private partnerships in cybercrime, as well as the vulnerability of crypto users to clipboard-based attacks. The operation also highlights the importance of endpoint security and user vigilance in the crypto ecosystem.
Source: CoinDesk