CryptoMedium2 September 2026
1 min read

CrowdStrike and US Authorities Dismantle Russian Crypto-Theft Malware

Key Facts

1CrowdStrike and federal authorities dismantled the Russia-based Sality malware that targeted Bitcoin and Ethereum addresses for eight years.
2More than 15,000 infected machines were isolated after the malware was found replacing copied wallet addresses with those of the attackers.

In a move reflecting the growing collaboration between cybersecurity firms and law enforcement to combat cross-border digital crime, CrowdStrike and US federal authorities successfully dismantled the Russia-based Sality malware. According to reports, this malware targeted Bitcoin and Ethereum addresses for eight years by monitoring clipboard data and replacing legitimate wallet addresses with those controlled by attackers to divert funds.

The security operation resulted in the isolation of more than 15,000 infected machines that the malware utilized as part of its attack infrastructure. This dismantling represents a significant security victory for the crypto ecosystem and marks a major corporate milestone for CrowdStrike in its collaboration with federal law enforcement. These developments come at a time of heightened market sensitivity toward cyber threats targeting digital assets.

Regarding market performance, CRWD stock stood at $215.07 (close September 1, 2026), after reaching a day high of $231.3. With no immediate upcoming economic catalysts in the calendar specifically related to the cybersecurity sector, traders will monitor support and resistance levels based on the recent trading range between $212.65 and $231.3.