CrowdStrike and federal law enforcement agencies have dismantled the Russian Sality botnet, a long-running malware network that hijacked cryptocurrency transfers by swapping copied BTC and ETH addresses on infected devices. The malware had been active since 2003 and spent the past eight years monitoring clipboards to redirect funds to attacker-controlled wallets.
CrowdStrike said the linked addresses stole at least 12.1 million rubles, or about $150,000, while untouched holdings had appreciated to roughly $1.35 million by early 2025. In a live demonstration, the team exploited weaknesses in Sality’s node identity verification and severed more than 15,000 infected devices from the botnet, which spread through peer-to-peer communication, LAN sharing, and USB drives without a central server.
CrowdStrike, U.S. Agencies Disrupt Sality Botnet Used in BTC, ETH Clipboard Theft
免責事項: Phemexニュースで提供されるコンテンツは、あくまで情報提供を目的としたものであり、第三者の記事から取得した情報の正確性・完全性・信頼性について保証するものではありません。本コンテンツは金融または投資の助言を目的としたものではなく、投資に関する最終判断はご自身での調査と、信頼できる専門家への相談を踏まえて行ってください。
