Crypto News

Sality botnet takedown halts new malware, but EggJagger address‑swap remains active

Sep 09, 2026 00:11 malware crypto security sality eggagger
Sality botnet takedown halts new malware, but EggJagger address‑swap remains active

Sality botnet disruption stops new malware but address‑swapping tool stays active

On August 31, a coordinated operation cut off the Sality botnet’s ability to deliver new malicious software. However, the malware already present on infected computers can still change cryptocurrency payment addresses.

Key facts

  • Disruption blocked new payload delivery to more than 33,000 compromised machines.
  • The EggJagger tool watches the clipboard and replaces copied Bitcoin or Ethereum addresses with ones controlled by the attacker.
  • Existing infections must be removed because the address‑swap feature continues to work.

CrowdStrike findings

CrowdStrike’s September 1 report says the operation isolated infected bots by inserting sinkhole servers and changing peer lists, preventing further instructions. The firm describes Sality as a file‑infector that spreads via network shares, removable drives, and file‑sharing services. It also provides YARA detection rules and advises checking for UDP traffic to the lighthouse address 188.166.101.148 to identify infections.

Justice Department and international partners

The U.S. Justice Department announced the multinational takedown on September 1, 2026, seizing Sality‑linked domains. Partners in Bulgaria, Hungary and Romania acted against additional domains. The Shadowserver Foundation is working with ISPs and incident‑response teams to locate infections and notify affected users.

How the address‑swap works

EggJagger runs on the victim’s computer and monitors the clipboard. When a user copies a crypto address to make a payment, the tool silently replaces it with an address owned by the attacker. If the user then pastes the address into a wallet or exchange, the funds are sent to the attacker’s wallet instead of the intended recipient.

What remains risky

Because the address‑swap code is already installed, the threat persists even after the botnet’s command‑and‑control servers are blocked. Infected devices still need to be cleaned to stop the malicious behavior.

Why users should act

Anyone who may have been infected should run anti‑malware scans, apply the YARA rules provided by CrowdStrike, and verify that no unauthorized crypto addresses appear in their clipboard history before sending payments.

Next steps for remediation

The Justice Department and Shadowserver Foundation are helping users identify infections. Security teams are advised to monitor network logs for the specific UDP traffic and to remove the EggJagger component from affected machines.

Sources

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!