CrowdStrike Dismantles Sality Botnet After Eight Years of Crypto Heists
Sality Botnet, active since 2003, has been dismantled by CrowdStrike and the Justice Department. The botnet spent its last eight years hijacking cryptocurrency payments by rewriting wallet addresses on infected computers.
The primary cargo of Sality was EggJagger, a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and swaps them with the operator's own. A victim copying a Bitcoin or Ethereum address to pay someone sends the money to a stranger.
CrowdStrike estimates that EggJagger alone earned at least 12.1 million rubles, roughly $150,000. The stolen coins were largely left untouched, which turned out to be the more profitable decision for the operator.