Crypto news report · source clearly identified
Copy‑Paste Crypto Address Swapping Malware Persists After Sality Botnet Disruption
CrowdStrike reports that the August 31 takedown of the Sality botnet stopped new payload delivery, but the address‑swapping tool already installed on infected computers continues to threaten users by redirecting Bitcoin and Ethereum payments.

On August 31, law‑enforcement actions disrupted the Sality botnet, cutting off its operator’s ability to deliver new malicious code to the more than 33,000 compromised machines worldwide. However, CrowdStrike’s September 1 analysis warns that a component of the malware – a clipboard‑monitoring tool that swaps cryptocurrency payment addresses – remains active on infected devices.
How the address‑swapping tool works
The payload, known as EggJagger, watches the system clipboard for copied cryptocurrency addresses. When a user copies a Bitcoin or Ethereum address to make a payment, the tool replaces it with an address controlled by the attackers. If the user then pastes the address into a payment form, the funds are sent to the malicious destination.
Impact of the botnet disruption
The operation, announced by the U.S. Justice Department on September 1, isolated infected machines by sinkholing the botnet’s peer‑to‑peer communication channels. This prevented further payload downloads and direct file transfers from the operator. Partners in Bulgaria, Hungary and Romania also seized Sality‑linked domains and took down URLs hosting malicious files.
Remaining risk and remediation steps
Because EggJagger is already resident on compromised computers, the address‑swapping risk persists even after the botnet’s command‑and‑control infrastructure is disabled. CrowdStrike advises users to:
- Scan for the malware using the provided YARA detection rules.
- Check network logs for UDP traffic to the Sality lighthouse address 188.166.101.148, which indicates infection.
- Remove the malicious files and any infected executables that the botnet may have attached to.
What users should watch for
Any unexpected change in a copied cryptocurrency address before confirming a transaction should be treated as suspicious. Users are encouraged to verify addresses manually or use QR‑code scanning where possible to avoid clipboard‑based attacks.
Source & attribution
News Source
- Publisher
- CryptoSlate
- Original date
- September 8, 2026, 2:35 PM
- Original headline
- Active crypto address “copy and paste attack” threatens users even after major malware cleanup cut off hackers