Crypto news report · source clearly identified

Copy‑Paste Crypto Address Swapping Malware Persists After Sality Botnet Disruption

CrowdStrike reports that the August 31 takedown of the Sality botnet stopped new payload delivery, but the address‑swapping tool already installed on infected computers continues to threaten users by redirecting Bitcoin and Ethereum payments.

On August 31, law‑enforcement actions disrupted the Sality botnet, cutting off its operator’s ability to deliver new malicious code to the more than 33,000 compromised machines worldwide. However, CrowdStrike’s September 1 analysis warns that a component of the malware – a clipboard‑monitoring tool that swaps cryptocurrency payment addresses – remains active on infected devices.

How the address‑swapping tool works

The payload, known as EggJagger, watches the system clipboard for copied cryptocurrency addresses. When a user copies a Bitcoin or Ethereum address to make a payment, the tool replaces it with an address controlled by the attackers. If the user then pastes the address into a payment form, the funds are sent to the malicious destination.

Impact of the botnet disruption

The operation, announced by the U.S. Justice Department on September 1, isolated infected machines by sinkholing the botnet’s peer‑to‑peer communication channels. This prevented further payload downloads and direct file transfers from the operator. Partners in Bulgaria, Hungary and Romania also seized Sality‑linked domains and took down URLs hosting malicious files.

Remaining risk and remediation steps

Because EggJagger is already resident on compromised computers, the address‑swapping risk persists even after the botnet’s command‑and‑control infrastructure is disabled. CrowdStrike advises users to:

  • Scan for the malware using the provided YARA detection rules.
  • Check network logs for UDP traffic to the Sality lighthouse address 188.166.101.148, which indicates infection.
  • Remove the malicious files and any infected executables that the botnet may have attached to.
The Justice Department noted that the Shadowserver Foundation is coordinating with ISPs and incident‑response teams to identify infections, notify affected users and support remediation.

What users should watch for

Any unexpected change in a copied cryptocurrency address before confirming a transaction should be treated as suspicious. Users are encouraged to verify addresses manually or use QR‑code scanning where possible to avoid clipboard‑based attacks.

Source & attribution

News Source

Publisher
CryptoSlate
Original date
September 8, 2026, 2:35 PM
Original headline
Active crypto address “copy and paste attack” threatens users even after major malware cleanup cut off hackers
View original report ↗