US Officials Disrupt Sality Malware Network Behind $150K Crypto Theft
US officials have joined forces with cybersecurity company CrowdStrike to take down entities behind malware used in cryptocurrency theft. The action was part of an international effort involving Bulgarian, Hungarian, and Romanian authorities, as well as private sector partners CrowdStrike and the Shadowserver Foundation.
The malware, known as Sality, has been operational since 2003 and has installed malicious software on compromised devices. According to CrowdStrike, in the previous eight years, entities behind Sality used a 'clipjacking tool' called EggJagger to steal at least $150,000 in cryptocurrency.
The clipjacking tool monitored victims' clipboard for cryptocurrency wallet addresses and silently replaced them with addresses controlled by the operator. This allowed criminals to redirect funds when victims made payments using Bitcoin or Ethereum addresses.
As a result of authorities' efforts, the entities behind Sality lost the ability to communicate with infected machines, effectively disrupting their network. The malware was used not only for cryptocurrency theft but also formed part of a peer-to-peer botnet consisting of about 15,000 infected computers that checked its systems every 40 minutes.