Huo Xing Cai Jing reports that the U.S. cybersecurity firm CrowdStrike, in collaboration with federal law enforcement agencies, recently dismantled the Russian-linked Sality malware botnet. This malware has been active since 2003 and has consistently hijacked cryptocurrency payments on infected computers over the past eight years. Its core payload, known as EggJagger, monitors the clipboard and replaces any text resembling Bitcoin or Ethereum addresses with addresses controlled by the attackers. Victims unknowingly send funds to the attackers when pasting transaction addresses. Sality has no central server that can be seized; infected devices communicate directly with each other, checking for peer availability every 40 minutes and spreading via network shares and USB drives. CrowdStrike exploited a security flaw in this mechanism by replacing the server with legitimate peer addresses, disconnecting over 15,000 infected devices from the network. The operation was demonstrated live at the CrowdStrike Day Zero summit in Las Vegas on Monday, with the U.S. Department of Justice stating the action was based on intelligence related to Russia. CrowdStrike estimates that the attackers stole at least 12.1 million rubles (approximately $150,000) over eight years; most of the stolen cryptocurrency remained untouched, and as prices rose, the value of these unspent assets reached approximately $1.35 million in early 2025. Authorities urge users to verify the first and last characters of cryptocurrency addresses after pasting them to guard against such clipboard hijacking attacks.
CrowdStrike and U.S. Federal Agencies Shut Down Russian Malware That Stole Cryptocurrency for Eight Years
MarsBitShare
CrowdStrike and U.S. federal agencies have dismantled the Russian-backed Sality botnet, which stole cryptocurrency for eight years. The malware, active since 2003, used clipboard hijacking to redirect crypto payments via EggJagger. Sality spread through peer-to-peer networks and removable drives. A vulnerability in its network enabled CrowdStrike to isolate 15,000 infected devices. The U.S. Department of Justice stated the operation was based in Russia. The attackers stole approximately $150,000, with $135,000 in assets remaining untouched as of early 2025. The takedown aligns with CFT efforts and affects liquidity and crypto markets.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.
