TechNewsReel
Live

DOJ and CrowdStrike Dismantle Sality Botnet After Years of Crypto Theft

A joint operation isolated over 15,000 infected machines across four countries to stop the theft of Bitcoin and Ethereum.

TechNewsReel Newsroom · September 2, 2026

The U.S. Department of Justice and cybersecurity firm CrowdStrike have collaborated to dismantle the Sality botnet, ending a long-running campaign of digital asset theft. The operation successfully isolated more than 15,000 infected machines across four different countries.

According to the DOJ, the takedown spanned the United States, Bulgaria, Hungary, and Romania. The botnet utilized a specific payload known as EggJagger to target and steal cryptocurrency from its victims, specifically focusing on Bitcoin and Ethereum. While the Sality malware family has been active since 2003, the DOJ noted that its primary focus on cryptocurrency theft had occurred over the last eight years.

The Evolution of Sality

Sality is a long-standing family of malware recognized for its ability to spread through removable drives and network shares. Historically, it has functioned as a downloader, providing a gateway for other malicious payloads to enter a system. In this recent iteration, the malware evolved to target cryptocurrency wallets, reflecting a broader industry trend where malware authors shift toward the direct theft of digital assets for immediate financial gain.

Implications for Cybersecurity

This takedown underscores the critical role of public-private partnerships in neutralizing persistent global threats. By combining the legal authority of the DOJ with the technical intelligence of a private firm like CrowdStrike, authorities were able to disrupt a network that had remained resilient for years. The scale of the operation—affecting thousands of machines across multiple jurisdictions—demonstrates the difficulty of eradicating deeply embedded botnets once they achieve global reach.

The Risk to Digital Asset Holders

For the cryptocurrency community, the Sality case highlights a significant vulnerability: the risk of long-term, silent infections. Because the botnet operated for years before being dismantled, it proves that assets can be drained over an extended period without the user's knowledge. This emphasizes the need for robust wallet security and the realization that traditional malware families can pivot their objectives to target modern financial technologies.

What Remains

While the isolation of 15,000 machines marks a major victory, the longevity of the Sality family suggests that malware authors often adapt and re-emerge. Security experts will continue to monitor for new variants of the Sality code and similar payloads that target digital wallets. The DOJ's operation serves as a blueprint for future international collaborations aimed at disrupting the financial incentives of cybercrime.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.