Russian Botnet Sality Dismantled After 20-Year Crypto Theft Campaign
A 20-year-old Russian botnet called Sality has been dismantled by federal authorities and CrowdStrike, a cybersecurity firm. The botnet operated from 2003 until its takedown in September 2026, using a tactic known as clipboard hijacking to steal cryptocurrency.
The attackers used a program called EggJagger to monitor clipboard activity on infected systems. Whenever a user copied a cryptocurrency wallet address to initiate a transaction, the malicious software substituted it with an attacker-controlled wallet. This allowed the attackers to accumulate approximately $150,000 worth of Bitcoin and Ethereum over eight years.
However, when cryptocurrency valuations surged in January 2025, the value of the stolen cryptocurrency reached around $1.5 million. In total, the attackers extracted at least 12.1 million rubles through clipboard hijacking activities.