CrowdStrike, Feds Dismantle Russian Malware That Hijacked Crypto Addresses for 8 Years

CrowdStrike and federal authorities have successfully dismantled a Russia-based malware operation known as Sality that operated covertly for approximately eight years. The malware was designed to monitor clipboard activity, detecting when users copied Bitcoin or Ethereum wallet addresses and silently replacing them with addresses controlled by the attackers. This technique, commonly known as a clipboard hijacker, allowed the threat actors to redirect cryptocurrency transactions without victims' knowledge. Investigators have identified and isolated more than 15,000 infected machines as part of the takedown effort.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.




Discussion (0)
Log in to join the discussion and vote.
Log in