U.S. cybersecurity firm CrowdStrike and federal law enforcement have dismantled Sality, a Russia-based botnet that hijacked cryptocurrency payments by replacing copied wallet addresses with those controlled by attackers over an eight-year period. The operation isolated more than 15,000 infected computers and recovered stolen funds estimated at approximately $150,000 in cryptocurrency.
Market Context
The takedown represents one of the longer-running cryptocurrency theft operations ever disrupted, operating quietly since approximately 2016 without attracting significant attention from the broader crypto market. The malware targeted everyday users copying and pasting wallet addresses rather than institutional players or exchange infrastructure, making it a persistent but low-profile threat to retail cryptocurrency holders.
Analysis
Sality's primary payload, which CrowdStrike dubbed 'EggJagger,' operated with deceptive simplicity. The malware sat dormant on infected machines, monitoring the clipboard for strings resembling bitcoin (BTC) or ether (ETH) addresses. When detected, it silently replaced the copied text with an address belonging to the attacker before the user pasted it into their wallet interface. By the time a victim reviewed their transaction, funds had already been sent to a malicious actor with no way to reverse the transfer.
The botnet's architecture made traditional takedown methods ineffective. Unlike conventional malware operations that rely on centralized command-and-control servers, Sality operated as a peer-to-peer network where infected machines communicated directly with one another every 40 minutes to verify peer availability. The system required no identity verification beyond expected response patterns.
CrowdStrike exploited this decentralized design by introducing its own servers into the peer communication loop, replacing legitimate peer addresses with CrowdStrike-controlled infrastructure and effectively severing connections between compromised machines without requiring physical access to each device.
"Any computer that responded in the expected way was treated as part of the botnet, with no further identity check," according to documentation from the operation. "CrowdStrike used that flaw to replace the real peer addresses with its own servers."
Key Numbers
- $150,000: Estimated value of stolen cryptocurrency at current exchange rates (12.1 million rubles)
- 15,000+: Infected machines disconnected during the takedown operation
- $1.35M: Peak value of unspent stolen holdings in early 2025 as crypto prices appreciated
- 8 years: Duration of the cryptocurrency hijacking operation before disruption
- 40 minutes: Interval between peer-to-peer botnet communication checks
What to Watch
Security researchers expect increased scrutiny on clipboard-monitoring malware following this high-profile takedown. Traders and investors should verify the first and last characters of any copied wallet address before initiating transactions, a simple defensive measure that would have prevented all losses from this attack vector. Further coordination between CrowdStrike and international law enforcement agencies may yield additional botnet disruptions in coming months.