CrowdStrike and federal law enforcement dismantled Sality, a Russia-based malware operation that quietly stole cryptocurrency for roughly eight years. The malware watched for copied bitcoin and Ethereum addresses and silently replaced them with the attacker's own, redirecting funds during transactions.
CoinDesk