A Russia-based malware operation known as Sality spent years targeting cryptocurrency users by monitoring copied wallet addresses and secretly swapping them for addresses controlled by attackers. CrowdStrike and U.S. law enforcement have now disrupted the network, isolating more than 15,000 compromised computers.
Cybersecurity company CrowdStrike worked with federal authorities to dismantle Sality, a botnet that has existed since 2003 and spent the past eight years targeting crypto transactions on infected devices.
The technique relied on a basic weakness in how people use cryptocurrency. Bitcoin and Ethereum wallet addresses are lengthy and difficult to enter manually, so users typically copy and paste them when sending funds.
Sality’s primary malware component, which CrowdStrike identified as “EggJagger,” monitored the clipboard on infected computers. Whenever it detected text that appeared to be a Bitcoin or Ethereum address, it automatically replaced the copied address with one controlled by the attackers.
If a user pasted the altered address into a crypto wallet and approved the transaction, the funds were sent directly to the attacker. There was generally no warning and, once the transaction was confirmed, no practical way to reverse it. CrowdStrike recommends that crypto users verify the beginning and ending characters of a wallet address after pasting it before every transaction.
The company estimates the operation generated at least 12.1 million Russian rubles, equivalent to roughly $150,000, over the eight-year period. Much of the stolen cryptocurrency was not immediately moved, and appreciation in crypto prices pushed the value of the dormant funds as high as about $1.35 million by early 2025.
Although the amount stolen was relatively modest, the campaign demonstrates how a straightforward attack technique can remain effective for years by exploiting routine user behavior.
Sality was also designed without a traditional centralized command server that authorities could simply seize. Instead, infected computers communicated directly with one another and checked roughly every 40 minutes to determine whether other known peers remained active.
The malware could spread by attaching itself to software distributed through network drives and USB devices, allowing the botnet to reproduce without requiring continuous intervention from its operators.
Machines that responded as expected were automatically accepted as members of the network, without an additional identity-verification step.
CrowdStrike exploited this weakness during the takedown by replacing legitimate peer addresses with servers under its control. The move effectively separated more than 15,000 infected machines from the wider botnet.
Authorities said the disruption was conducted Monday as part of a live demonstration during CrowdStrike’s Day Zero cybersecurity summit in Las Vegas.
Officials said the malware operation was based in Russia.

More Stories
Bitcoin and XRP Pull Back as Bearish “Bart Simpson” Pattern Returns
Bitcoin Drops Below $76,500 as Iran Strikes Push Oil Past $93
Liz Truss Warns Bond Market Rout Could Trigger Emergency UK Spending Cuts