CrowdStrike and federal law enforcement agencies have dismantled the Russian Sality botnet, a long-running malware network that hijacked cryptocurrency transfers by swapping copied BTC and ETH addresses on infected devices. The malware had been active since 2003 and spent the past eight years monitoring clipboards to redirect funds to attacker-controlled wallets.
CrowdStrike said the linked addresses stole at least 12.1 million rubles, or about $150,000, while untouched holdings had appreciated to roughly $1.35 million by early 2025. In a live demonstration, the team exploited weaknesses in Sality’s node identity verification and severed more than 15,000 infected devices from the botnet, which spread through peer-to-peer communication, LAN sharing, and USB drives without a central server.
CrowdStrike, U.S. Agencies Disrupt Sality Botnet Used in BTC, ETH Clipboard Theft
Aviso Legal: O conteúdo disponibilizado no Phemex News é apenas para fins informativos. Não garantimos a qualidade, precisão ou integridade das informações provenientes de artigos de terceiros. Este conteúdo não constitui aconselhamento financeiro ou de investimento. Recomendamos fortemente que você realize suas próprias pesquisas e consulte um consultor financeiro qualificado antes de tomar decisões de investimento.
