XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Regulation
● Regulation

Federal Authorities Take Down Sality Malware Operation, Disrupting Years of Cryptocurrency Theft

U.S. federal authorities and cybersecurity firms have successfully disrupted a major malware operation that stole cryptocurrency from unsuspecting users over eight years through sophisticated clipboard manipulation tactics.

JM
by Jacob Marquez · Regulation Desk
Published September 3, 2026 · 2 min read

The Long-Running Sality Operation

The Sality botnet, active since 2003 in distributing malware to compromised devices, has been successfully disrupted through a coordinated international enforcement action. According to the U.S. Justice Department, federal authorities collaborated with cybersecurity company CrowdStrike and additional private sector partners including the Shadowserver Foundation to announce the takedown. The effort involved coordination with authorities in Bulgaria, Hungary, and Romania, underscoring the global coordination required to dismantle sophisticated cybercriminal infrastructure.

The operation targeting Sality represents a significant achievement for law enforcement and cybersecurity professionals working to protect digital assets. Across the previous eight years, malware operators leveraged the botnet to target cryptocurrency holdings, successfully stealing at least 12.1 million rubles—approximately $150,000—in digital assets. Analysis of holdings seized during the operation revealed accumulated cryptocurrency with a peak value near $1.5 million during January 2025.

The Clipjacking Attack Method

At the heart of the theft operation was EggJagger, a malicious program functioning as a clipjacking tool designed specifically to intercept cryptocurrency transactions. As reported by CrowdStrike, the malware monitored users’ clipboard memory, automatically intercepting any cryptocurrency wallet addresses copied in preparation for transfers. When victims attempted to send Bitcoin or Ethereum, the malware would silently substitute legitimate wallet addresses with addresses controlled by the criminal operators.

This technique proved devastatingly effective because users remained unaware their transactions were being redirected. Victims believed they were completing legitimate cryptocurrency transfers to intended recipients, only discovering later that their funds had been diverted to attacker-controlled wallets.

Infrastructure Dismantled

CrowdStrike’s investigation revealed the scale of compromised infrastructure supporting the operation. Approximately 15,000 computers across the globe had been infected and incorporated into a peer-to-peer botnet serving the malware operators’ command structure. These compromised devices maintained regular contact with control servers, checking for updated instructions approximately every 40 minutes to coordinate ongoing theft operations and malware propagation.

The successful disruption operation severed communications between operators and their infected machine network, effectively neutralizing the botnet’s operational capability. This action prevents future cryptocurrency theft attempts through this particular malware family and eliminates the operational infrastructure previously controlled by the criminals. When international law enforcement successfully dismantles malware networks targeting cryptocurrency holders, it strengthens confidence in digital asset security and demonstrates that coordinated enforcement action can effectively protect the broader crypto ecosystem.

Source: U.S. Justice Department, via Cointelegraph. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Regulation Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.