CrowdStrike and federal authorities dismantle Russian malware targeting crypto for 8 years

59 minutes ago 16

A coordinated strike by CrowdStrike, the DOJ, the FBI, and European law enforcement has dismantled a peer-to-peer botnet that spent nearly a decade silently stealing cryptocurrency from thousands of compromised devices. The operation, which began on August 31 and was formally announced on September 1, targeted the Sality botnet and its crypto-focused payload known as EggJagger.

The malware’s trick was deceptively simple: it monitored victims’ clipboards for copied wallet addresses and swapped them with addresses controlled by the attackers. You’d copy your friend’s Bitcoin address, paste it into your wallet app, and unknowingly send funds straight to a criminal. The operator behind the scheme, tracked under the name SALTY SPIDER and assessed to be based in Russia, managed to siphon at least 12.1 million rubles (roughly $150K) through this method alone.

Two decades of infection, eight years of crypto theft

Sality has been lurking since 2003, making it ancient by malware standards. Over its lifetime, it infected more than 15,000 devices and was used for the full buffet of cybercrime: spam campaigns, distributed denial-of-service attacks, and eventually cryptocurrency theft.

The pivot to crypto came about eight years ago, when the EggJagger payload was deployed across the botnet’s infrastructure.

What made Sality particularly difficult to kill was its architecture. Unlike botnets that rely on a central command-and-control server, Sality operated on a peer-to-peer model. Each infected device communicated directly with other infected devices, creating a decentralized web of malware that could survive the loss of any single node.

The takedown involved isolating infected machines and seizing domains critical to the botnet’s operations, effectively cutting off the network’s ability to propagate and coordinate.

Following the money

While confirmed thefts via clipboard hijacking totaled around $150K, the unspent cryptocurrency holdings tied to Sality’s wallets peaked at approximately 147 million rubles, or about $1.35 million, as of January 2025.

The SALTY SPIDER operator wasn’t exclusively focused on stealing from retail crypto users, either. CrowdStrike’s research indicated the botnet was involved in DDoS attacks against various targets, including a Russian cryptocurrency exchange in 2023.

The cleanup and what comes next

The Shadowserver Foundation is now assisting with victim notification and remediation efforts following the takedown. For the 15,000-plus devices that were part of the Sality network, the process of cleaning infections and securing systems is just beginning.

CrowdStrike provided the threat intelligence and technical analysis, while the DOJ, FBI, and European partners handled the legal authorities needed to seize infrastructure and coordinate across jurisdictions.

Whether SALTY SPIDER faces prosecution remains an open question, given the operator’s assessed location in Russia.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article