CrowdStrike and Feds Disrupt Decade-Old Botnet Stealing Cryptocurrency
A coordinated effort by CrowdStrike and federal authorities has dismantled the Sality botnet, which had been silently stealing cryptocurrency from thousands of compromised devices for nearly a decade. The operation targeted the botnet's crypto-focused payload known as EggJagger.
The malware worked by monitoring victims' clipboards for copied wallet addresses and swapping them with addresses controlled by the attackers. This allowed the operator behind the scheme to siphon at least 12.1 million rubles (approximately $150,000) in cryptocurrency through this method alone.
Sality has been lurking since 2003, making it ancient by malware standards. Over its lifetime, it infected more than 15,000 devices and was used for various cybercrimes, including spam campaigns and distributed denial-of-service attacks.