Crypto news report · source clearly identified

CrowdStrike and Authorities Disrupt Russian Sality Malware Targeting Crypto Addresses

The Sality malware, operating from Russia, intercepted copied Bitcoin and Ethereum addresses and swapped them for attacker‑controlled ones. CrowdStrike and law enforcement have now isolated over 15,000 infected machines.

Security firm CrowdStrike, together with federal law‑enforcement agencies, has taken down a Russian‑based malware campaign that covertly hijacked cryptocurrency transactions for eight years.

How the malware operated

The malicious code, known as Sality, monitored clipboard activity for copied Bitcoin and Ethereum addresses. When a user pasted an address, the malware silently replaced it with an address controlled by the attackers, diverting funds to their wallets.

Scale of the infection

Investigators report that more than 15,000 computers were compromised by the Sality strain before the operation was disrupted.

Response and mitigation

CrowdStrike worked with law‑enforcement partners to isolate the infected machines and halt further address substitution. Users are advised to verify cryptocurrency addresses before confirming transactions, especially when copying and pasting them.

Source & attribution

News Source

Publisher
CoinDesk
Original date
September 2, 2026, 1:14 PM
Original headline
CrowdStrike and federal authorities dismantle Russian malware that secretly stole crypto for 8 years
View original report ↗