CrowdStrike and federal law enforcement agencies have dismantled the Russian Sality botnet, a long-running malware network that hijacked cryptocurrency transfers by swapping copied BTC and ETH addresses on infected devices. The malware had been active since 2003 and spent the past eight years monitoring clipboards to redirect funds to attacker-controlled wallets.
CrowdStrike said the linked addresses stole at least 12.1 million rubles, or about $150,000, while untouched holdings had appreciated to roughly $1.35 million by early 2025. In a live demonstration, the team exploited weaknesses in Sality’s node identity verification and severed more than 15,000 infected devices from the botnet, which spread through peer-to-peer communication, LAN sharing, and USB drives without a central server.
CrowdStrike, U.S. Agencies Disrupt Sality Botnet Used in BTC, ETH Clipboard Theft
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
