September 02, 13:14

CrowdStrike and federal authorities dismantle Sality malware

Russian malware that secretly stole BTC, ETH for 8 years gets dismantled by CrowdStrike and federal authorities

CoinDesk

CrowdStrike and federal law enforcement dismantled Sality, a botnet that operated since 2003. Sality hijacked cryptocurrency payments on infected computers during its final eight years. CrowdStrike estimated that attackers stole at least 12.1 million rubles, or about $150,000, over eight years. Sality's main payload, called EggJagger by CrowdStrike, monitored infected computers' clipboards. EggJagger replaced copied bitcoin or ether addresses with addresses controlled by the attacker. Victims could send funds to the attacker without receiving a warning or having a way to reverse the transaction. Users can check the first and last characters of a cryptocurrency address after pasting it. Much of the stolen cryptocurrency remained untouched. The value of those unspent holdings reached as much as $1.35 million in early 2025 as cryptocurrency prices climbed.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.