CrowdStrike Takes Down Russia-Based Botnet Stealing Cryptocurrency for Eight Years
CrowdStrike and U.S. federal law enforcement have taken down Sality, a botnet that operated for over two decades and spent its last eight years quietly stealing cryptocurrency from everyday users.
The malware used a tool called EggJagger to swap copied crypto wallet addresses with attacker-controlled ones.
Over 15,000 infected machines were cut off from the botnet during a live operation in Las Vegas. The attackers stole at least $150,000 in Bitcoin and Ethereum over eight years via clipboard hijacking.
The stolen funds peaked in value at around $1.5 million in January 2025 as prices rose.