TLDR
- Federal authorities partnered with CrowdStrike to eliminate Sality, a Russian botnet operational for more than 20 years
- Cybercriminals deployed EggJagger, a clipjacking program that replaced cryptocurrency wallet addresses with fraudulent ones
- Attackers accumulated approximately $150,000 worth of Bitcoin and Ethereum through eight years of clipboard manipulation
- The value of hoarded stolen cryptocurrency reached approximately $1.5 million during the January 2025 market surge
- More than 15,000 compromised computers were disconnected from the criminal network during a live demonstration in Las Vegas
CrowdStrike collaborated with United States federal investigators to dismantle Sality, a criminal botnet that operated for more than twenty years, dedicating its final eight years to systematically siphoning cryptocurrency from unsuspecting victims.
The scheme functioned by monitoring clipboard activity on infected systems. Whenever a user copied a cryptocurrency wallet address to initiate a transaction, the malicious software substituted it with an attacker-controlled wallet. Victims would unknowingly paste the fraudulent address, authorize the transfer, and send their digital assets directly to the criminals without any indication of compromise.
The Mechanics Behind the Attack
EggJagger served as the primary weapon in this operation. According to CrowdStrike’s analysis, this clipjacking utility operated covertly on compromised systems, constantly surveilling clipboard data for cryptocurrency addresses.
Cryptocurrency wallet addresses consist of lengthy alphanumeric sequences. Virtually nobody manually enters these addresses, creating a vulnerability that attackers ruthlessly exploited.
The infection vector relied on shared network resources and removable storage devices. The malware embedded itself within legitimate applications and maintained persistence through self-replication mechanisms that required no user interaction.
Unlike traditional botnets, Sality operated without centralized command infrastructure, complicating takedown efforts. The decentralized architecture enabled infected systems to communicate directly with one another, conducting status checks approximately every 40 minutes to maintain network connectivity.
The Disruption Strategy
Security researchers at CrowdStrike identified a vulnerability within the peer-to-peer communication protocol. By substituting legitimate peer addresses with company-controlled infrastructure, investigators successfully isolated over 15,000 infected devices from the criminal network.
The disruption occurred Monday during a real-time presentation at CrowdStrike’s Day Zero conference in Las Vegas.
The Department of Justice publicly disclosed the operation Tuesday. The coordinated takedown involved international cooperation from Bulgarian, Hungarian, and Romanian authorities, alongside private sector contributions from CrowdStrike and the Shadowserver Foundation.
According to DOJ statements, the infrastructure was based in Russia, with Sality actively distributing malware to compromised systems since 2003.
Throughout eight years of clipboard hijacking activities, the criminal operators extracted at least 12.1 million rubles, equivalent to approximately $150,000 in digital currency. A substantial percentage of these illicit proceeds remained untouched in the attackers’ wallets.
When cryptocurrency valuations surged, the worth of these dormant holdings escalated to roughly $1.5 million during their January 2025 zenith.
This takedown illustrates how surprisingly simple techniques, like address substitution, can evade detection for extended periods.
Cryptocurrency users can safeguard their assets by verifying the initial and final characters of wallet addresses immediately after pasting, before authorizing any transaction.
According to CrowdStrike’s assessment, the operators behind Sality no longer possess the capability to interact with infected devices following the successful disruption campaign.
The post Russian Crypto-Stealing Botnet Sality Shut Down After Two-Decade Run appeared first on Blockonomi.
Source: https://blockonomi.com/russian-crypto-stealing-botnet-sality-shut-down-after-two-decade-run/





Be the first to comment