{"id":12959,"date":"2026-09-08T14:52:34","date_gmt":"2026-09-08T14:52:34","guid":{"rendered":"https:\/\/cryptonews.uk.com\/?p=12959"},"modified":"2026-09-08T14:52:34","modified_gmt":"2026-09-08T14:52:34","slug":"sality-botnet-disrupted-but-crypto-stealing-malware-remains","status":"publish","type":"post","link":"https:\/\/cryptonews.uk.com\/?p=12959","title":{"rendered":"Sality botnet disrupted, but crypto-stealing malware remains"},"content":{"rendered":"<p><\/p>\n<div data-single-article-content=\"\">\n<p>The Aug. 31 disruption of the Sality botnet cut off its operator&#8217;s ability to deliver new malicious software to infected computers, while malware already on those devices remained active, according to CrowdStrike&#8217;s Sept. 1 report. Users of infected machines still need to remove the installed malware, including a tool that swaps cryptocurrency addresses and can redirect payments.<\/p>\n<p>CrowdStrike said the botnet enabled payload distribution to more than 33,000 infected machines worldwide. The figure measures compromised computers; the number of users who lost cryptocurrency remains unspecified.<\/p>\n<p>The Justice Department announced the multinational operation on Sept. 1, 2026, following the action the previous day. U.S. authorities seized Sality-linked domains, while partners in Bulgaria, Hungary and Romania acted against additional domains.<\/p>\n<h2>How the payment risk survives<\/h2>\n<p>CrowdStrike identified EggJagger as Sality&#8217;s primary payload over the preceding eight years. The tool watches the clipboard for cryptocurrency addresses and substitutes ones controlled by the operator, including when someone copies a Bitcoin or Ethereum address for a payment.<\/p>\n<p>The dangerous step is sending to the substituted address. A user can intend to pay the correct recipient yet paste a different destination into the payment form. The redirection takes effect if the user sends funds to that destination.<\/p>\n<div class=\"cs-article-embed\">\n<p> <span class=\"cs-article-embed__related-reading\">Related Reading<\/span><\/p>\n<h3 class=\"cs-article-embed__title\">CryptoBandits malware lets criminals use your USB drive to access crypto wallets \u2013 Microsoft warns<\/h3>\n<\/p>\n<p> <span class=\"cs-article-embed__arrow\" aria-hidden=\"true\"> <i class=\"fa-light fa-arrow-up-right\"\/> <\/span> <\/div>\n<p>Address-swapping software already installed on a computer can keep operating after Sality&#8217;s communications are cut off. Users with a confirmed infection therefore still need to have the malware removed from their devices.<\/p>\n<aside id=\"cs-inline-newsletter-1\" class=\"cs-inline-newsletter\" data-inline-newsletter=\"\" data-newsletter-placement=\"article-midpoint\" data-newsletter-pending-label=\"Joining\u2026\" data-newsletter-pending-status=\"Joining the Daily Brief\u2026\" data-newsletter-email-required-message=\"Before sending, please provide your email address.\" aria-labelledby=\"cs-inline-newsletter-1-title\" aria-describedby=\"cs-inline-newsletter-1-copy\">\n<div class=\"cs-inline-newsletter__inner\">\n<div class=\"cs-inline-newsletter__content\"> <span class=\"cs-inline-newsletter__eyebrow\"> <i class=\"fa-regular fa-envelope\" aria-hidden=\"true\"\/> The Daily Brief <\/span><\/p>\n<h2 id=\"cs-inline-newsletter-1-title\" class=\"cs-inline-newsletter__title\">The signal, before the noise.<\/h2>\n<p id=\"cs-inline-newsletter-1-copy\" class=\"cs-inline-newsletter__copy\">Start your day with the crypto stories moving markets, decoded by CryptoSlate\u2019s editors.<\/p>\n<\/div>\n<div class=\"cs-inline-newsletter__form-shell\">\n<p class=\"cs-inline-newsletter__form-heading\">One email. Everything that matters.<\/p>\n<p id=\"cs-inline-newsletter-1-privacy\" class=\"cs-inline-newsletter__privacy\">Free to join. Unsubscribe any time.<\/p>\n<p> <i class=\"fa-regular fa-circle-xmark\" aria-hidden=\"true\"\/> <span>Whoops, looks like there was a problem. Please try again.<\/span><\/p>\n<p> <i class=\"fa-regular fa-circle-check\" aria-hidden=\"true\"\/> <span><strong>You\u2019re on the list.<\/strong> Your next Daily Brief is on its way.<\/span><\/p>\n<\/div>\n<\/div>\n<\/aside>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-560753\" src=\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/09\/exec-1171420a-38be-4a2a-af30-e4e34c0f99e5.png\" alt=\"Sality disruption on Aug. 31, 2026 blocked new payload delivery, while installed EggJagger can swap copied payment addresses. The flow shows payment redirection if the user sends to the substituted address, followed by detection and malware removal.\" width=\"720\" height=\"1080\" srcset=\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/09\/exec-1171420a-38be-4a2a-af30-e4e34c0f99e5.png 1024w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/09\/exec-1171420a-38be-4a2a-af30-e4e34c0f99e5-200x300.png 200w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/09\/exec-1171420a-38be-4a2a-af30-e4e34c0f99e5-683x1024.png 683w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/09\/exec-1171420a-38be-4a2a-af30-e4e34c0f99e5-768x1152.png 768w\" sizes=\"(max-width: 720px) 100vw, 720px\"\/><img decoding=\"async\" class=\"lazyload aligncenter wp-image-560753\" src=\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/09\/exec-1171420a-38be-4a2a-af30-e4e34c0f99e5.png\" alt=\"Sality disruption on Aug. 31, 2026 blocked new payload delivery, while installed EggJagger can swap copied payment addresses. The flow shows payment redirection if the user sends to the substituted address, followed by detection and malware removal.\" width=\"720\" height=\"1080\" srcset=\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/09\/exec-1171420a-38be-4a2a-af30-e4e34c0f99e5.png 1024w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/09\/exec-1171420a-38be-4a2a-af30-e4e34c0f99e5-200x300.png 200w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/09\/exec-1171420a-38be-4a2a-af30-e4e34c0f99e5-683x1024.png 683w, https:\/\/cryptoslate.com\/wp-content\/uploads\/2026\/09\/exec-1171420a-38be-4a2a-af30-e4e34c0f99e5-768x1152.png 768w\" data-sizes=\"(max-width: 720px) 100vw, 720px\"\/><\/p>\n<p>CrowdStrike describes Sality as a file infector: it attaches to executable files and spreads through network shares, removable drives and file sharing. Those infected files are a separate problem from the network connections disrupted by the operation.<\/p>\n<p>The disruption changed the lists of peers that infected machines use to communicate, isolating them from the operator and inserting defender-controlled servers known as sinkholes. CrowdStrike said isolated bots could no longer receive payload download instructions or direct transfers of malicious files. Partners also took down URLs hosting payloads.<\/p>\n<p>For network operators, CrowdStrike recommends checking network logs and device telemetry for UDP traffic to its lighthouse address, <code>188.166.101[.]148<\/code>. The company says a match indicates a Sality infection requiring remediation. Its technical report also provides YARA detection rules for scanning running processes.<\/p>\n<div class=\"cs-article-embed\">\n<p> <span class=\"cs-article-embed__related-reading\">Related Reading<\/span><\/p>\n<h3 class=\"cs-article-embed__title\">40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools<\/h3>\n<\/p>\n<p> <span class=\"cs-article-embed__arrow\" aria-hidden=\"true\"> <i class=\"fa-light fa-arrow-up-right\"\/> <\/span> <\/div>\n<p>The Justice Department said the Shadowserver Foundation is working with internet service providers and computer security incident response teams to identify infections and help notify affected users and support remediation.<\/p>\n<p>For users of infected computers, remediation addresses the malware that can still replace a copied payment address. The botnet disruption alone leaves that local threat in place.<\/p>\n<div class=\"cs-article-embed\">\n<p> <span class=\"cs-article-embed__related-reading\">Related Reading<\/span><\/p>\n<h3 class=\"cs-article-embed__title\">Spot the crypto scam before you hit send<\/h3>\n<\/p>\n<p> <span class=\"cs-article-embed__arrow\" aria-hidden=\"true\"> <i class=\"fa-light fa-arrow-up-right\"\/> <\/span> <\/div>\n<\/div>\n<p>Crime,Featured,Payments,Bitcoin,BTC,CrowdStrike,ETH,ethereum,paymentsBitcoin,BTC,CrowdStrike,ETH,ethereum,payments#Sality #botnet #disrupted #cryptostealing #malware #remains1788879154<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Aug. 31 disruption of the Sality botnet cut off its operator&#8217;s ability to deliver new malicious software to infected computers, while malware already on those devices remained active, according to CrowdStrike&#8217;s Sept. 1 report. Users of infected machines still need to remove the installed malware, including a tool that swaps cryptocurrency addresses and can<\/p>\n","protected":false},"author":1,"featured_media":12960,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[91,6800,285,6658,6801,922,601,31,3332,167,704,6799],"class_list":["post-12959","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ethereum","tag-bitcoin","tag-botnet","tag-btc","tag-crowdstrike","tag-cryptostealing","tag-disrupted","tag-eth","tag-ethereum","tag-malware","tag-payments","tag-remains","tag-sality"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.6 (Yoast SEO v26.6) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Sality botnet disrupted, but crypto-stealing malware remains - Crypto News: Latest Cryptocurrency News and Analysis<\/title>\n<meta name=\"description\" content=\"The Sality botnet disruption blocked new payloads, CrowdStrike says, but installed crypto-address-swapping malware still needs removal.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.uk.com\/?p=12959\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sality botnet disrupted, but crypto-stealing malware remains\" \/>\n<meta property=\"og:description\" content=\"The Sality botnet disruption blocked new payloads, CrowdStrike says, but installed crypto-address-swapping malware still needs removal.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.uk.com\/?p=12959\" \/>\n<meta property=\"og:site_name\" content=\"Crypto News: Latest Cryptocurrency News and Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-08T14:52:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/sality-crypto-address-swap.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"\u884c\u653f\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u884c\u653f\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12959\",\"url\":\"https:\/\/cryptonews.uk.com\/?p=12959\",\"name\":\"Sality botnet disrupted, but crypto-stealing malware remains - Crypto News: Latest Cryptocurrency News and Analysis\",\"isPartOf\":{\"@id\":\"https:\/\/cryptonews.uk.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12959#primaryimage\"},\"image\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12959#primaryimage\"},\"thumbnailUrl\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/sality-crypto-address-swap.jpg\",\"datePublished\":\"2026-09-08T14:52:34+00:00\",\"author\":{\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf\"},\"description\":\"The Sality botnet disruption blocked new payloads, CrowdStrike says, but installed crypto-address-swapping malware still needs removal.\",\"breadcrumb\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12959#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/cryptonews.uk.com\/?p=12959\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12959#primaryimage\",\"url\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/sality-crypto-address-swap.jpg\",\"contentUrl\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/sality-crypto-address-swap.jpg\",\"width\":1280,\"height\":720},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=12959#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/cryptonews.uk.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Sality botnet disrupted, but crypto-stealing malware remains\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/cryptonews.uk.com\/#website\",\"url\":\"https:\/\/cryptonews.uk.com\/\",\"name\":\"Crypto News: Latest Cryptocurrency News and Analysis\",\"description\":\"Latest Crypto &amp; Bitcoin News\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/cryptonews.uk.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf\",\"name\":\"\u884c\u653f\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g\",\"caption\":\"\u884c\u653f\"},\"sameAs\":[\"http:\/\/demo3.aiwalls.com\/coinbase\"],\"url\":\"https:\/\/cryptonews.uk.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Sality botnet disrupted, but crypto-stealing malware remains - Crypto News: Latest Cryptocurrency News and Analysis","description":"The Sality botnet disruption blocked new payloads, CrowdStrike says, but installed crypto-address-swapping malware still needs removal.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.uk.com\/?p=12959","og_locale":"en_US","og_type":"article","og_title":"Sality botnet disrupted, but crypto-stealing malware remains","og_description":"The Sality botnet disruption blocked new payloads, CrowdStrike says, but installed crypto-address-swapping malware still needs removal.","og_url":"https:\/\/cryptonews.uk.com\/?p=12959","og_site_name":"Crypto News: Latest Cryptocurrency News and Analysis","article_published_time":"2026-09-08T14:52:34+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/sality-crypto-address-swap.jpg","type":"image\/jpeg"}],"author":"\u884c\u653f","twitter_card":"summary_large_image","twitter_misc":{"Written by":"\u884c\u653f","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/cryptonews.uk.com\/?p=12959","url":"https:\/\/cryptonews.uk.com\/?p=12959","name":"Sality botnet disrupted, but crypto-stealing malware remains - Crypto News: Latest Cryptocurrency News and Analysis","isPartOf":{"@id":"https:\/\/cryptonews.uk.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.uk.com\/?p=12959#primaryimage"},"image":{"@id":"https:\/\/cryptonews.uk.com\/?p=12959#primaryimage"},"thumbnailUrl":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/sality-crypto-address-swap.jpg","datePublished":"2026-09-08T14:52:34+00:00","author":{"@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf"},"description":"The Sality botnet disruption blocked new payloads, CrowdStrike says, but installed crypto-address-swapping malware still needs removal.","breadcrumb":{"@id":"https:\/\/cryptonews.uk.com\/?p=12959#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.uk.com\/?p=12959"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptonews.uk.com\/?p=12959#primaryimage","url":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/sality-crypto-address-swap.jpg","contentUrl":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/09\/sality-crypto-address-swap.jpg","width":1280,"height":720},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.uk.com\/?p=12959#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.uk.com\/"},{"@type":"ListItem","position":2,"name":"Sality botnet disrupted, but crypto-stealing malware remains"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.uk.com\/#website","url":"https:\/\/cryptonews.uk.com\/","name":"Crypto News: Latest Cryptocurrency News and Analysis","description":"Latest Crypto &amp; Bitcoin News","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.uk.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf","name":"\u884c\u653f","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g","caption":"\u884c\u653f"},"sameAs":["http:\/\/demo3.aiwalls.com\/coinbase"],"url":"https:\/\/cryptonews.uk.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts\/12959","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=12959"}],"version-history":[{"count":0,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts\/12959\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/media\/12960"}],"wp:attachment":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=12959"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=12959"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=12959"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}