U.S. cybersecurity company CrowdStrike and federal law enforcement have dismantled the Russia-linked Sality malware botnet, which had been operating since 2003 and hijacking cryptocurrency payments on infected computers for the past eight years. According to ChainCatcher, the malware’s core payload, EggJagger, monitored the clipboard and replaced text resembling Bitcoin or Ethereum addresses with attacker-controlled addresses, causing victims to send funds to the wrong destination when pasting transfer details.
Sality had no central server to seize and instead relied on direct communication between infected devices, checking peer nodes every 40 minutes and spreading through network shares and USB drives. CrowdStrike said it exploited a security flaw in that mechanism to replace the botnet’s servers with legitimate peer addresses, cutting off more than 15,000 infected devices from the network. The operation was demonstrated live on Monday at CrowdStrike’s Day Zero summit in Las Vegas, and the U.S. Department of Justice said the action was based in Russia.
CrowdStrike estimated that attackers stole at least 12.1 million rubles over eight years. Most of the stolen cryptocurrency was not spent, and its value rose to about $1.35 million in early 2025 as prices increased. Officials advised users to check the first and last characters of a cryptocurrency address after pasting it to help detect clipboard hijacking attacks.