GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

CrowdStrike Teams With Law Enforcement to Dismantle Russian Cryptojacking Botnet Sality

Source: www.coindesk.com Event types: Security/Hacker
According to CoinDesk, US cybersecurity firm CrowdStrike has partnered with federal law enforcement agencies to successfully dismantle the Russian botnet Sality, which has been operating for over two decades. Over the past eight years, the network has continuously stolen cryptocurrency through clipboard hijacking; its core payload, "EggJagger," resides on infected machines, monitoring the user's clipboard. Once a Bitcoin or Ethereum wallet address is detected, it is replaced with the attacker's address, causing victims to unknowingly complete transfers. Sality employs a decentralized P2P architecture with no central server, checking node online status every 40 minutes, and self-propagates via network-shared drives and USB devices. By exploiting an authentication vulnerability, CrowdStrike replaced legitimate node addresses with those of its own servers, successfully severing the network connections of over 15,000 infected machines. The operation was demonstrated live at the Day Zero summit in Las Vegas. Estimates indicate that the attackers stole at least 12.1 million rubles (approximately $150,000) over the eight-year period. Undisturbed crypto assets appreciated alongside the broader market, reaching a value of roughly $1.35 million by early 2025. Security experts advise users to always verify the first and last characters after pasting a wallet address to defend against such attacks.

Related projects