The U.S. cybersecurity firm CrowdStrike, in collaboration with federal law enforcement, has dismantled Sality, a botnet that operated since 2003 and spent its last 8 years hijacking cryptocurrency payments. The malware, based in Russia, replaced copied Bitcoin and Ethereum addresses on infected machines with the attacker's own addresses. The operation, carried out on Monday, isolated over 15,000 infected machines. CrowdStrike estimates the attackers stole at least $150,000, with unspent holdings later rising to $1.35 million in early 2025.