American cybersecurity enterprise CrowdStrike and United States federal law enforcement have dismantled Sality, a botnet active since 2003 that spent its final 8 years intercepting digital asset transfers on compromised systems.
The specific attack vector utilized is straightforward enough that the vast majority of cryptocurrency users remain vulnerable to it. Destination addresses consist of lengthy alphanumeric strings that nobody inputs manually, leading individuals to rely on copying and pasting.
The primary payload of Sality, designated as ‘EggJagger’ by CrowdStrike, resided on infected devices while monitoring the clipboard. Upon detecting a string resembling an ether or bitcoin destination, it swapped the copied data with a string controlled by the threat actor.
An unsuspecting individual pasting into their software wallet and executing the transfer ended up funding a malicious operator without any alert or method of reversal. One effective safeguard for users is verifying the initial and concluding characters of an address following a paste action every single time.
CrowdStrike calculated that the culprits misappropriated at least 12.1 million rubles, equivalent to roughly $150,000, across an eight-year timeframe. A significant portion of the digital assets was left untouched, and the valuation of those dormant funds subsequently climbed as high as $1.35 million by early 2025 as market valuations increased.
Although this financial figure is relatively modest, it highlights how an uncomplicated scheme persisted for eight years by taking advantage of everyday participants who copied extended destination codes rather than typing them out or carefully inspecting them.
Furthermore, Sality lacked any master command server for authorities to confiscate. Compromised systems communicated directly with one another, querying every 40 minutes to verify if their known peers remained active. The malware propagated by attaching itself to applications distributed across shared network volumes and USB flash drives, multiplying autonomously without intervention from its creators.
Any hardware that responded appropriately was categorized as a node within the botnet, requiring no extra verification of identity.
CrowdStrike leveraged this exact vulnerability to substitute genuine peer nodes with their own infrastructure, isolating more than 15,000 compromised computers from the network. Officials reported that this operation was executed on Monday during a live presentation at the Day Zero conference hosted by CrowdStrike in Las Vegas.
The department noted that the operation originated out of Russia.
Originally published at https://www.coindesk.com/tech/2026/09/02/crowdstrike-and-federal-authorities-dismantle-russian-malware-that-secretly-stole-crypto-for-8-years.