
CrowdStrike disrupts malware linked to $150,000 crypto theft
- US authorities and CrowdStrike disrupted the Sality malware network after an international operation.
- The malware redirected at least US$150,000 in cryptocurrency over eight years, according to CrowdStrike.
- The operation isolated infected machines from the criminal network and disrupted further payload distribution.
CrowdStrike helped US and international authorities disrupt Sality, a malware network linked to at least US$150,000 in crypto theft.
The Sality botnet has operated since 2003 and infected more than 15,000 machines worldwide, according to CrowdStrike.
CrowdStrike said that when victims copied Bitcoin (CRYPTO:BTC) or Ethereum (CRYPTO:ETH) addresses for payments, EggJagger redirected the funds.
The company said its EggJagger malware replaced copied wallet addresses with addresses controlled by the operator.
CrowdStrike said the stolen cryptocurrency reached at least 12.1 million Russian roubles, while its unspent holdings peaked near US$1.5 million in January 2025.
Following the operation, the source did not report a specific CrowdStrike share-price reaction.
US officials, CrowdStrike and other partners used a peer-to-peer sinkhole operation to isolate infected machines and disrupt Sality's communications.
At the time of reporting, Bitcoin price was $77,150.28.



