Russian Botnet Disrupted After Eight Years of Stealing Crypto
A Russian-linked botnet called Sality has been dismantled by CrowdStrike in collaboration with U.S. law enforcement, who disrupted its operations after eight years of stealing cryptocurrency.
The malware, known as EggJagger, targeted cryptocurrency users' clipboard activity, replacing copied Bitcoin and Ethereum wallet addresses with ones controlled by the attackers.
According to CrowdStrike, Sality has been operating since 2003, but its operators added a component in 2017 designed to intercept cryptocurrency transfers. The botnet exploited a common practice among crypto users of copying long wallet addresses rather than entering them manually.
The scheme's operators received at least 12.1 million rubles ($150,000) over eight years and more than $1.35 million in stolen cryptocurrency value by early 2025 as the market gained.