CrowdStrike and federal authorities dismantle Russian malware that secretly stole crypto for 8 years

U.S. cybersecurity firm CrowdStrike and federal law enforcement have announced the dismantling of Sality, a long-running botnet that has operated since 2003 and spent its last eight years hijacking cryptocurrency payments on infected computers. According to CoinDesk, the operation has isolated more than 15,000 infected machines.

The technique behind the crypto theft was notably simple. Wallet addresses are long alphanumeric strings that almost nobody types by hand, so users routinely copy and paste them. Sality's main payload of recent years, which CrowdStrike calls "EggJagger," sat quietly on infected machines and monitored the clipboard. When it detected something resembling a bitcoin or ether address, it replaced the copied text with an address controlled by the attacker. A victim who pasted the address into a wallet and hit send would pay the malicious actor instead of the intended recipient, with no warning shown and no way to reverse the transfer. CrowdStrike describes EggJagger as a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and swaps them for the operator's own.

The financial haul was modest by the standards of major crypto hacks. CrowdStrike estimated the attackers stole at least 12.1 million rubles, roughly $150,000, over the eight-year period through this method. However, much of the stolen crypto was reportedly left untouched, and the value of those unspent holdings later rose to as much as $1.35 million in early 2025 as crypto prices climbed. The relatively small figure underscores a broader point: a very basic trick worked for the better part of a decade simply by exploiting the everyday habit of copying long wallet addresses rather than inspecting them.

Sality's history stretches well beyond crypto. Before EggJagger, the botnet earned its keep delivering credential theft, spam distribution, proxy services, network exploitation and denial-of-service payloads, according to a technical writeup CrowdStrike published alongside the takedown. Its longevity was aided by its architecture — the botnet had no central command server for authorities to seize, which had historically made disruption difficult.

The takedown was a multinational effort. Per Decrypt, actions were announced in the United States, Bulgaria, Hungary and Romania, carried out in collaboration with private industry partners including CrowdStrike. The Justice Department, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the U.S., while police in Bulgaria, Hungary and Romania took down others in Europe. The Shadowserver Foundation is working with internet service providers to notify victims whose machines were compromised. Infected machines now report to CrowdStrike-controlled sinkholes rather than to the botnet's operator — a standard technique that redirects malicious traffic to servers run by defenders.

CrowdStrike tracks the operator behind the botnet under the name SALTY SPIDER. The firm reported that the operator occasionally turned the botnet against targets of their own choosing. One example cited: a denial-of-service payload deployed in September 2023 against AvanChange, a Russian cryptocurrency exchange, which was compiled seconds before upload — behavior CrowdStrike interprets as an impulsive reaction to a personal grievance. The firm believes the operator used exchanges of that kind to convert stolen coins into cash.

CrowdStrike has published detection rules and network indicators to help defenders identify related activity. For ordinary crypto users, the practical takeaway highlighted in coverage of the case is straightforward: after pasting a wallet address, verify the first and last characters of the address against the original before confirming any transaction, every single time. Clipboard-hijacking malware remains one of the lowest-effort, highest-persistence attack methods against retail crypto holders precisely because the swap is invisible unless the user checks.

The disruption removes one long-running piece of infrastructure, though researchers involved have cautioned that malware families of this type tend to be replaced rather than eliminated outright.

This is a news summary for general information only — not financial advice, and nothing here is a recommendation to buy, sell, or hold any asset. Always verify against the original source and do your own research before making a financial decision.

Source: CoinDesk · 2026-09-02