U.S. cybersecurity firm CrowdStrike and federal law enforcement disrupted the Russia-based Sality botnet, which for eight years diverted bitcoin and ether transactions by swapping copied wallet addresses with those controlled by attackers. Operating without a central server, Sality infected computers through network shares and USB drives. Its EggJagger payload monitored clipboards for cryptocurrency addresses, then substituted attacker wallets, helping steal at least 12.1 million rubles, roughly $150,000, in digital assets. Investigators exploited a flaw in Sality’s peer-to-peer design to isolate over 15,000 infected machines during a live operation in Las Vegas. The takedown highlights the need for users to verify wallet address characters after pasting transactions.
This update represents a notable development in the Crypto sector. Organizations and founders tracking this space should evaluate potential strategic and technical implications on their operations.