U.S. cybersecurity firm CrowdStrike and federal law enforcement agencies have dismantled Sality, a long-running malware botnet that spent years hijacking cryptocurrency transactions by secretly replacing wallet addresses copied by victims.
Sality has operated since 2003, but over the past eight years it increasingly targeted crypto payments through a payload CrowdStrike identified as “EggJagger.” The malware monitored infected computers’ clipboards for copied Bitcoin or Ethereum wallet addresses.
When EggJagger detected a cryptocurrency address, it automatically replaced it with one controlled by the attackers. Victims who pasted the altered address into a crypto wallet and approved the transaction unknowingly transferred their funds to malicious actors. Because blockchain transactions generally cannot be reversed, users had little recourse after sending the funds.
CrowdStrike estimated that Sality operators stole at least 12.1 million Russian rubles, worth roughly $150,000, during the eight-year period. Much of the stolen cryptocurrency remained untouched, with the value of those holdings climbing to as much as $1.35 million in early 2025 as digital asset prices increased.
The relatively modest amount highlights how a straightforward clipboard-hijacking attack can remain effective for years. Crypto users can reduce the risk by verifying the first and last characters of a wallet address after pasting it and before approving every transaction.
Disrupting Sality presented an additional challenge because the botnet did not rely on a central command-and-control server. Infected computers communicated directly with one another, checking approximately every 40 minutes whether known peers remained online. The malware also spread through infected programs on network drives and USB devices.
CrowdStrike exploited a weakness in Sality’s peer-verification system, which treated any computer responding correctly as a legitimate botnet member without further authentication. Researchers replaced genuine peer addresses with CrowdStrike-controlled servers, isolating more than 15,000 infected computers from the network.
The takedown was conducted Monday during a live demonstration at CrowdStrike’s Day Zero summit in Las Vegas. U.S. authorities said the Sality operation was based in Russia.
Comment 0