CrowdStrike And DOJ Take Down Sality Botnet In Major Crypto Crackdown

TL;DR
- CrowdStrike and the Department of Justice dismantled Sality, a botnet active since 2003 that operated for eight years stealing cryptocurrencies.
- The malicious tool EggJagger replaced wallet addresses in the clipboard, redirecting Bitcoin and Ethereum payments to the attacker’s accounts.
- Authorities isolated more than 15,000 infected machines across four countries; the unspent cryptocurrencies peaked at $1.35 million.
CrowdStrike and the United States Department of Justice announced the dismantling of Sality, a botnet active since 2003 that spent its last eight years intercepting cryptocurrency payments through the manipulation of wallet addresses on infected computers. The operation also involved the FBI, the Defense Criminal Investigative Service, and law enforcement agencies from Bulgaria, Hungary, and Romania.
The central mechanism of the theft was EggJagger, a tool that monitored the clipboard of each compromised machine. When a victim copied a Bitcoin or Ethereum address to make a transfer, EggJagger replaced it in real time with an address controlled by the attacker. The funds reached the thief’s hands without the user noticing any difference.
… Continue reading the full article at the original source below.



