Advertisement

Russian Malware That Stole Crypto for Eight Years Taken Down by CrowdStrike and Feds

CrowdStrike and U.S. law enforcement have disrupted Sality, a long-running Russian-linked botnet that secretly redirected cryptocurrency transfers by replacing copied Bitcoin and Ethereum wallet addresses with attacker-controlled ones.

The botnet has been active since 2003, but for roughly the past eight years it was used to target crypto transactions on compromised computers. CrowdStrike said the operation affected more than 15,000 machines, which authorities have now separated from the malicious network.

Sality relied on a relatively simple attack method. Because cryptocurrency wallet addresses are long and difficult to type manually, users commonly copy and paste them when making transfers.

The malware component behind the crypto theft, which CrowdStrike named “EggJagger,” continuously monitored the clipboard. When it detected a string resembling a Bitcoin or Ethereum address, it replaced the legitimate address with one belonging to the attacker.

As a result, a user could paste what appeared to be their intended wallet address and approve a transaction without realizing that the destination had been changed. Once the payment was confirmed, recovering the funds was generally impossible.

Users can reduce the risk by checking at least the beginning and ending characters of a wallet address after pasting it and before confirming a transaction.

CrowdStrike estimates that the attackers obtained at least 12.1 million Russian rubles, or approximately $150,000, during the eight-year cryptocurrency campaign. Some of the stolen funds remained dormant, however, and the value of those holdings reportedly reached as much as $1.35 million in early 2025 as cryptocurrency prices increased.

While the estimated theft may appear limited, the campaign highlights how effective a basic clipboard attack can remain when it targets routine cryptocurrency habits over an extended period.

Sality did not depend on a conventional centralized command-and-control server. Instead, infected computers communicated directly with other compromised machines and periodically checked whether known peers were still connected.

The malware could also spread through software shared on network drives and USB devices, enabling the botnet to expand without requiring constant involvement from its operators.

There was another weakness in the system: computers that responded correctly to the botnet’s communications were automatically accepted as legitimate peers without additional authentication.

CrowdStrike used that weakness during the disruption operation. The company redirected the botnet’s peer addresses to servers controlled by its own team, effectively cutting more than 15,000 infected computers off from the malicious network.

Authorities said the operation took place Monday during a live demonstration at CrowdStrike’s Day Zero summit in Las Vegas.

The U.S. Department of Justice said the operation was connected to Russia, bringing an end to a cryptocurrency theft campaign that had remained active for years.