Federal Crackdown Ends Long-Running Russian Malware Campaign That Stole Cryptocurrency
CrowdStrike and U.S. authorities have disrupted Sality, a Russia-based malware network that allegedly diverted cryptocurrency payments for eight years by secretly swapping copied wallet addresses for those controlled by criminals.
Sality has been around since 2003, but its more recent activity turned toward crypto theft. CrowdStrike said the operation had compromised more than 15,000 computers, all of which have now been separated from the malicious network.
The attack took advantage of a routine practice among cryptocurrency users. Bitcoin and Ethereum wallet addresses are lengthy strings of characters, so most people copy and paste them instead of entering them manually.
The malware responsible for the scheme, which CrowdStrike called “EggJagger,” ran in the background and monitored the clipboard. When it detected a string that appeared to be a crypto wallet address, it replaced the legitimate address with one belonging to the attackers.
A victim could therefore paste the altered address into a wallet and approve a transaction without realizing the destination had changed. Since blockchain transfers are generally irreversible, there was little opportunity to recover the funds once the transaction was completed.
CrowdStrike advises users to verify the beginning and ending characters of an address after pasting it and before confirming any cryptocurrency transfer.
The company estimates the campaign generated at least 12.1 million Russian rubles, or about $150,000, over eight years. However, some of the stolen cryptocurrency was left untouched, and rising crypto prices pushed the value of those dormant holdings to approximately $1.35 million by early 2025.
The relatively modest amount of stolen funds does not make the campaign insignificant. It demonstrates how criminals can repeatedly exploit a simple user habit and remain effective for an extended period.
Sality was built as a decentralized botnet rather than one controlled through a single central server. Infected devices communicated directly with other compromised machines and checked their known peers roughly every 40 minutes.
The malware also spread through software distributed on network drives and USB devices, allowing the infection to move between systems without continuous intervention from its operators.
Another weakness was the network’s limited authentication. A computer that responded in the expected way could be accepted as a botnet peer without undergoing additional identity checks.
CrowdStrike exploited this weakness during the takedown by replacing legitimate peer addresses with servers it controlled. The move disrupted communications and disconnected more than 15,000 infected machines from Sality.
Authorities said the operation was carried out Monday during a live demonstration at CrowdStrike’s Day Zero summit in Las Vegas.
U.S. officials identified the operation as Russia-based, disrupting a malware network that had remained active for more than 20 years and had spent a significant portion of that time targeting cryptocurrency users.
Share this content:













