Federal authorities and CrowdStrike have dismantled Sality, a Russian-based botnet with a very particular purpose: stealing cryptocurrency by changing the addresses users copy and paste during transactions. The joint law-enforcement action reported that more than 15,000 infected machines were isolated from the botnet. For roughly eight years, the criminals behind Sality watched as victims copied Bitcoin and Ethereum addresses into wallet interfaces and exchange fields. Then, in the blink of an eye, the malware replaced those addresses with ones controlled by the attackers.
Eight years of clipboard hijacking
The technique is known as clipboard hijacking or address replacement. It exploits a routine activity that almost every cryptocurrency user performs: copying a long alphanumeric address from an invoice, web page, chat message, or email and pasting it into a payment screen. Sality monitored the clipboard in real time. When it detected a pattern that looked like a Bitcoin or Ethereum address, it substituted a different address that had been prepared by the operator. The substitute was often structured to preserve the opening characters and sometimes the ending characters, so a victim who compared only part of the displayed address would see no obvious difference.
Most desktop wallets show the pasted address in a small box. A user may check the first few letters and the final few numbers, but the middle section can be ignored. The malicious address was selected from a pool of valid wallet addresses that the attacker controlled. When the victim confirmed the transaction, the digital asset left their wallet and traveled directly to the criminal's address. Because blockchain transactions cannot be reversed, the theft would only be discovered after the funds were already moved through exchanges or mixing services.
Despite the elegance of the scheme, the financial toll was relatively modest. Investigators linked Sality to at least 12.1 million rubles in crypto losses, which is about $150,000 over the full period. The figure likely undercounts the true total, because victims may not have reported all incidents or because some transactions were denominated in untracked cryptocurrencies. The small average payment may have helped the operation stay under the radar: it functioned as a long-tail scam rather than a single enormous hack.
Old malware with a new criminal module
Although Sality appeared in recent reports as a crypto botnet, its origins go back much further. Security researchers have tracked various versions of Sality since the early 2000s. The malware was classified as a file infector, meaning it could attach parts of its code to executable files.
Source: Coindesk News