CrowdStrike and U.S. Federal Agencies Take Down 8-Year-Old Russian Crypto-Stealing Malware

iconChaincatcher
Share
AI summary iconSummary
CrowdStrike and U.S. federal agencies dismantled Sality, an 8-year-old Russian malware designed to steal cryptocurrency through clipboard hijacking. Active since 2003, the malware exploited liquidity and crypto markets by replacing legitimate wallet addresses with those controlled by attackers. Its decentralized architecture made tracking difficult, but a flaw in its communication system enabled authorities to disconnect 15,000 infected devices. The U.S. Department of Justice connected the operation to Countering the Financing of Terrorism (CFT) efforts. Authorities estimate the attackers stole approximately $150,000 in rubles, with some funds still unrecovered. Users are advised to carefully verify wallet addresses to prevent clipboard hijacking attacks.

ChainCatcher report: The U.S. cybersecurity firm CrowdStrike, in coordination with federal law enforcement agencies, recently dismantled the Russian-linked Sality malware botnet. This malware has been active since 2003 and has consistently hijacked cryptocurrency payments on infected computers over the past eight years. Its core payload, known as EggJagger, monitors the clipboard and replaces any text resembling Bitcoin or Ethereum addresses with addresses controlled by the attackers. Victims unknowingly send funds to the attackers when pasting transaction addresses. Sality has no central server to seize; infected devices communicate directly with each other, checking peer connectivity every 40 minutes and spreading via network shares and USB drives. CrowdStrike exploited a security flaw in this mechanism by replacing the server with legitimate peer addresses, severing connections for over 15,000 infected devices. The operation was demonstrated live at the CrowdStrike Day Zero summit in Las Vegas on Monday. The U.S. Department of Justice stated the action was based on intelligence related to Russia. CrowdStrike estimates that the attackers stole at least 12.1 million rubles (approximately $150,000) over eight years; most of the stolen cryptocurrency remained untouched, and as prices rose, the value of these unspent assets reached approximately $1.35 million in early 2025. Authorities urge users to verify the first and last characters of cryptocurrency addresses after pasting them to guard against such clipboard hijacking attacks.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.