Russia-based Sality watched for copied bitcoin and Ethereum addresses and quietly replaced them with the attacker’s. CrowdStrike and law enforcement have now isolated more than 15,000 infected machines.
Brief · Source report
CrowdStrike and federal authorities dismantle Russian malware that secretly stole crypto for 8 years
