W3BStation
Markets
BTC $96,420 +2.34% ETH $3,280 +1.82% SOL $185.40 -0.92% BNB $642.50 +0.45% XRP $2.18 +3.12% DOGE $0.082 -1.50% ADA $1.05 +0.80% AVAX $42.10 +1.15%
BTC $96,420 +2.34% ETH $3,280 +1.82% SOL $185.40 -0.92% BNB $642.50 +0.45% XRP $2.18 +3.12% DOGE $0.082 -1.50% ADA $1.05 +0.80% AVAX $42.10 +1.15%
09/03/2026

CrowdStrike and DOJ Dismantle Russian Crypto-Stealing Botnet After 8 Years

What happened: CrowdStrike, in coordination with the U.

CrowdStrike and DOJ Dismantle Russian Crypto-Stealing Botnet After 8 Years

What happened: CrowdStrike, in coordination with the U.S. Department of Justice and international partners, dismantled the Russia-based Sality botnet and its EggJagger crypto-clipping malware. The operation, conducted August 31–September 1, 2026, severed more than 15,000 infected machines from the botnet, which had been silently replacing copied Bitcoin and Ethereum addresses on victim computers for approximately eight years. Confirmed theft totaled roughly 12.1 million rubles (about $150,000), though unspent wallet balances peaked at $1.35 million in early 2025.

Why it matters: While the dollar amount stolen is modest compared to other crypto hacks, the botnet's longevity—operating undetected for years—highlights persistent security gaps in user behavior and malware detection. The takedown demonstrates the effectiveness of international law enforcement collaboration and advanced sinkholing techniques against decentralized, peer-to-peer botnets. It also serves as a warning that clipboard-based attacks remain a real threat for crypto users.

Source: CoinDesk, CryptoBriefing, U.S. DOJ