A multinational operation on August 31, 2026, disrupted the Sality botnet, which had distributed payloads to over 33,000 infected machines worldwide. Coordinated by the U.S. Department of Justice and partners in Bulgaria, Hungary, and Romania, the takedown blocked new payload deliveries. However, previously installed malware remains active. Specifically, the EggJagger clipboard hijacker continues to swap copied cryptocurrency addresses, meaning infected users must still perform manual remediation.
Story comments
Loading comments…