CrowdStrike and federal law enforcement agencies have dismantled the Russian Sality botnet, a long-running malware network that hijacked cryptocurrency transfers by swapping copied BTC and ETH addresses on infected devices. The malware had been active since 2003 and spent the past eight years monitoring clipboards to redirect funds to attacker-controlled wallets.
CrowdStrike said the linked addresses stole at least 12.1 million rubles, or about $150,000, while untouched holdings had appreciated to roughly $1.35 million by early 2025. In a live demonstration, the team exploited weaknesses in Sality’s node identity verification and severed more than 15,000 infected devices from the botnet, which spread through peer-to-peer communication, LAN sharing, and USB drives without a central server.
CrowdStrike, U.S. Agencies Disrupt Sality Botnet Used in BTC, ETH Clipboard Theft
Tuyên bố miễn trừ trách nhiệm: Nội dung được cung cấp trên Phemex News chỉ nhằm mục đích cung cấp thông tin.Chúng tôi không đảm bảo chất lượng, độ chính xác hoặc tính đầy đủ của thông tin có nguồn từ các bài viết của bên thứ ba.Nội dung trên trang này không cấu thành lời khuyên về tài chính hoặc đầu tư.Chúng tôi đặc biệt khuyến khích bạn tự tiến hành nghiên cứu và tham khảo ý kiến của cố vấn tài chính đủ tiêu chuẩn trước khi đưa ra bất kỳ quyết định đầu tư nào.
