CrowdStrike Helps Dismantle Russian Malware Operation Targeting Crypto for Years

CrowdStrike and U.S. law enforcement have disrupted Sality, a Russia-based botnet accused of quietly redirecting cryptocurrency payments for roughly eight years by replacing copied wallet addresses with those controlled by attackers.

The malware network dates back to 2003, but its later activity increasingly focused on cryptocurrency theft. Investigators said more than 15,000 infected computers have now been cut off from the botnet.

Sality’s crypto campaign depended on a simple but effective tactic. Bitcoin and Ethereum addresses are long strings of characters that users generally copy and paste rather than enter manually, creating an opportunity for malware to interfere with transactions.

CrowdStrike said Sality’s main payload, dubbed “EggJagger,” monitored the clipboard on compromised computers. When it detected a string resembling a Bitcoin or Ethereum address, it automatically replaced the legitimate destination with an address controlled by the attacker.

A victim could then paste the modified address into a wallet and authorize the payment without noticing the substitution. Because blockchain transactions generally cannot be reversed after confirmation, the stolen funds were difficult to recover.

CrowdStrike recommends that cryptocurrency users verify the first and final characters of a wallet address after pasting it before approving a transfer.

The cybersecurity company estimates the attackers collected at least 12.1 million Russian rubles, equivalent to about $150,000, over the eight-year period. A substantial portion of the stolen cryptocurrency remained dormant, however, and its value climbed to roughly $1.35 million by early 2025 as digital-asset prices rose.

Although the estimated proceeds were relatively limited, the operation illustrates how criminals can exploit ordinary crypto habits for years using a comparatively straightforward technique.

Sality also differed from conventional botnets because it did not depend on a single command-and-control server. Compromised computers communicated directly with other infected machines and checked approximately every 40 minutes to see whether known peers remained available.

The malware could spread through programs shared over network drives and USB storage devices, helping it move between systems without requiring constant action from its operators.

Its peer-to-peer structure contained a significant security weakness: machines that responded in the expected manner were accepted into the network without undergoing additional authentication.

CrowdStrike used that weakness as part of the disruption operation, redirecting the botnet’s legitimate peer addresses to servers controlled by the company. This effectively severed communications for more than 15,000 compromised computers.

The operation was conducted Monday during a live demonstration at CrowdStrike’s Day Zero summit in Las Vegas, according to authorities.

U.S. officials said the malware operation was based in Russia, bringing a major disruption to a network that had been operating for more than two decades.

  • Related Posts

    Bitcoin and XRP Face Renewed Pressure With “Bart Simpson” Pattern Emerging

    The crypto market is seeing the return of a familiar chart formation, with traders pointing to a potential “Bart Simpson” pattern as bitcoin, XRP and ether retreat from recent highs.…

    Continue reading
    Bitcoin Slides as Surging Oil Prices Follow U.S. Strikes on Iran

    Bitcoin traded near $76,500 after falling more than 1% since midnight UTC, extending its seven-day decline to roughly 3%. The move came as intensified U.S. strikes on Iranian targets pushed…

    Continue reading