Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
CrowdStrike disruption blocks new crypto malware payloads but existing infections still threaten users
00

CrowdStrike disruption blocks new crypto malware payloads but existing infections still threaten users

Sep 8, 2026

A multinational operation on August 31, 2026, disrupted the Sality botnet, which had distributed payloads to over 33,000 infected machines worldwide. Coordinated by the U.S. Department of Justice and partners in Bulgaria, Hungary, and Romania, the takedown blocked new payload deliveries. However, previously installed malware remains active. Specifically, the EggJagger clipboard hijacker continues to swap copied cryptocurrency addresses, meaning infected users must still perform manual remediation.

Sality botnet disruption operation

  • ▪The Sality botnet disruption on August 31, 2026, isolated infected bots by changing peer lists and inserting defender-controlled sinkhole servers to block download instructions.
  • ▪The Sality botnet enabled payload distribution to more than 33,000 infected machines worldwide prior to its disruption on August 31, 2026.
  • ▪A multinational operation on August 31, 2026, disrupted the Sality botnet, cutting off its operator's ability to deliver new malicious payloads to infected computers.

EggJagger clipboard malware threat

  • ▪The EggJagger malware monitors a computer's clipboard and replaces copied cryptocurrency addresses, such as Bitcoin or Ethereum, with addresses controlled by the malware operator.
  • ▪CrowdStrike identified EggJagger as the Sality botnet's primary payload over the eight years preceding the August 2026 disruption.

Persistent infection remediation requirements

  • ▪The Sality malware acts as a file infector that attaches to executable files and spreads through network shares, removable drives, and file sharing.
  • ▪CrowdStrike recommends network operators check network logs and device telemetry for UDP traffic to the lighthouse address 188.166.101.148 to identify Sality infections.
  • ▪Because address-swapping malware like EggJagger already installed on a computer remains active after the Sality botnet disruption, infected devices still require manual malware removal.

Multi-agency takedown coordination

  • ▪During the Sality takedown, United States authorities seized Sality-linked domains, while international partners in Bulgaria, Hungary, and Romania acted against additional domains.
  • ▪The United States Department of Justice announced the multinational takedown of the Sality botnet on September 1, 2026.
  • ▪The Shadowserver Foundation is working with internet service providers and computer security incident response teams to identify Sality infections and support remediation.

1 source

Cryptoslate
Active crypto address "copy and paste attack" threatens users even after major malware cleanup cut off hackers
View source article

Story comments

Loading comments…

Related entities

Cybersecurity

Topics

Crypto securityCrypto payments