The operators behind the Sality botnet and malware used a “clipjacking tool“ to replace wallet addresses with ones they controlled, enabling the theft of thousands of dollars in crypto.