Russian malware stealing Bitcoin and Ethereum for 8 years dismantled by CrowdStrike and US authorities
Russian malware stealing Bitcoin and Ethereum for 8 years dismantled by CrowdStrike and US authorities
CrowdStrike and federal law enforcement have dismantled Sality, a Russia-based botnet that secretly stole cryptocurrency for eight years by replacing copied wallet addresses with those controlled by attackers.
The malware, active since 2003, used a payload called ‘EggJagger’ to monitor clipboards on infected computers. When it detected a Bitcoin or Ethereum address, it swapped it with an address owned by the attacker, tricking users into sending funds to the wrong destination.
A simple defense is to check the first and last characters of a pasted wallet address before sending cryptocurrency.
Over 15,000 infected machines isolated
Sality operated without a central server, spreading through network shares and USB drives. Infected machines communicated directly with each other, checking peer status every 40 minutes.
CrowdStrike exploited a flaw in this system, replacing real peer addresses with its own servers. This cut off more than 15,000 infected machines from the network during a live demonstration at CrowdStrike’s Day Zero summit in Las Vegas on Monday.
Stolen funds and unspent holdings
Attackers stole at least 12.1 million rubles, roughly $150,000, over eight years. Much of the stolen cryptocurrency remained untouched, and its value later rose to as much as $1.35 million in early 2025 as crypto prices increased.
Why this matters for crypto users
The case highlights a simple but effective trick: exploiting users who copy and paste long wallet addresses without verifying them. The botnet’s long operation shows how such attacks can go unnoticed for years.