Signal

Authorities dismantle malware botnet linked to crypto theft

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-09-02 11:30 UTCUpdated 2026-09-02 13:18 UTC
rsstelegram
crypto_securitymalwarebitcoinethereumlaw_enforcement
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
CoinDesk report
coindesk.com · coindesk.com · 2026-09-02 13:18 UTC
Decrypt report
decrypt.co · decrypt.co · 2026-09-02 11:30 UTC
limited source diversity in top sources
Overview

CrowdStrike and federal authorities reportedly dismantled the Sality botnet after eight years of crypto-related theft activity. The malware allegedly monitored copied Bitcoin and Ethereum addresses and replaced them with attacker-controlled addresses; more than 15,000 infected machines were isolated in the operation.

Entities
CrowdStrikeSalityBTCETH
Why now
  • The takedown was reported on September 2, 2026.
  • The operation brings a reported eight-year crypto theft campaign into focus.
Why it matters
  • Address-replacement malware can redirect crypto transfers before users notice.
  • The reported isolation of more than 15,000 machines limits the botnet’s active reach.
Evidence assessment
Recurring claims
  • Sality allegedly replaced copied Bitcoin and Ethereum addresses with attacker-controlled addresses.
  • CrowdStrike and federal authorities isolated more than 15,000 infected machines.
How sources frame it
  • CoinDesk: neutral
  • Decrypt: neutral
A reported malware takedown affecting cryptocurrency address handling and theft attempts.
All evidence
All evidence
CoinDesk report
coindesk.com · coindesk.com · 2026-09-02 13:18 UTC
Decrypt report
decrypt.co · decrypt.co · 2026-09-02 11:30 UTC
Show filters & breakdown
Evidence items loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 4