Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Ukrainian TV channel building hit by Russian drone as five killed in Kyiv

    September 8, 2026

    EU pursues closer Israel ties on air defense and space – POLITICO

    September 8, 2026

    Here in Liverpool, buses are back under public control – and that’s great for the only people who really matter | Steve Rotheram

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Ukrainian TV channel building hit by Russian drone as five killed in Kyiv
    • EU pursues closer Israel ties on air defense and space – POLITICO
    • Here in Liverpool, buses are back under public control – and that’s great for the only people who really matter | Steve Rotheram
    • Reform UK would ban full-face coverings in public areas
    • Richard Kelly on Donnie Darko at 25: ‘It’s a Miracle That Any Movie Gets Made’
    • SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability
    • Sality botnet disrupted, but crypto-stealing malware remains
    • Innocent-looking AI reasoning can make bad behavior harder to catch
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    Sality botnet disrupted, but crypto-stealing malware remains

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Crypto & Blockchain No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Aug. 31 disruption of the Sality botnet cut off its operator’s ability to deliver new malicious software to infected computers, while malware already on those devices remained active, according to CrowdStrike’s Sept. 1 report. Users of infected machines still need to remove the installed malware, including a tool that swaps cryptocurrency addresses and can redirect payments.

    CrowdStrike said the botnet enabled payload distribution to more than 33,000 infected machines worldwide. The figure measures compromised computers; the number of users who lost cryptocurrency remains unspecified.

    The Justice Department announced the multinational operation on Sept. 1, 2026, following the action the previous day. U.S. authorities seized Sality-linked domains, while partners in Bulgaria, Hungary and Romania acted against additional domains.

    How the payment risk survives

    CrowdStrike identified EggJagger as Sality’s primary payload over the preceding eight years. The tool watches the clipboard for cryptocurrency addresses and substitutes ones controlled by the operator, including when someone copies a Bitcoin or Ethereum address for a payment.

    The dangerous step is sending to the substituted address. A user can intend to pay the correct recipient yet paste a different destination into the payment form. The redirection takes effect if the user sends funds to that destination.

    Related Reading

    CryptoBandits malware lets criminals use your USB drive to access crypto wallets – Microsoft warns

    Address-swapping software already installed on a computer can keep operating after Sality’s communications are cut off. Users with a confirmed infection therefore still need to have the malware removed from their devices.

    The Daily Brief

    The signal, before the noise.

    Start your day with the crypto stories moving markets, decoded by CryptoSlate’s editors.

    One email. Everything that matters.

    Free to join. Unsubscribe any time.

    Whoops, looks like there was a problem. Please try again.

    You’re on the list. Your next Daily Brief is on its way.

    Sality disruption on Aug. 31, 2026 blocked new payload delivery, while installed EggJagger can swap copied payment addresses. The flow shows payment redirection if the user sends to the substituted address, followed by detection and malware removal.

    CrowdStrike describes Sality as a file infector: it attaches to executable files and spreads through network shares, removable drives and file sharing. Those infected files are a separate problem from the network connections disrupted by the operation.

    The disruption changed the lists of peers that infected machines use to communicate, isolating them from the operator and inserting defender-controlled servers known as sinkholes. CrowdStrike said isolated bots could no longer receive payload download instructions or direct transfers of malicious files. Partners also took down URLs hosting payloads.

    For network operators, CrowdStrike recommends checking network logs and device telemetry for UDP traffic to its lighthouse address, 188.166.101[.]148. The company says a match indicates a Sality infection requiring remediation. Its technical report also provides YARA detection rules for scanning running processes.

    Related Reading

    40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools

    The Justice Department said the Shadowserver Foundation is working with internet service providers and computer security incident response teams to identify infections and help notify affected users and support remediation.

    For users of infected computers, remediation addresses the malware that can still replace a copied payment address. The botnet disruption alone leaves that local threat in place.

    Related Reading

    Spot the crypto scam before you hit send

    Botnet CryptoStealing Disrupted Malware remains Sality
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Morning Minute: The Trenches Just Had Their Biggest Week Since TRUMP

    What Is LAPTOP? Hunter Biden’s Meme Coin Targeting TRUMP Holders

    Circle Targets Global Payments Growth With Tazapay Acquisition

    Polish Court Detains Fifth Suspect in Zondacrypto Exchange Probe

    Hunter Biden’s LAPTOP memecoin: launch and tokenomics

    Ethereum arbitrage: Builder receipts versus ETH burn

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Ukrainian TV channel building hit by Russian drone as five killed in Kyiv

    September 8, 2026

    EU pursues closer Israel ties on air defense and space – POLITICO

    September 8, 2026

    Here in Liverpool, buses are back under public control – and that’s great for the only people who really matter | Steve Rotheram

    September 8, 2026

    Reform UK would ban full-face coverings in public areas

    September 8, 2026
    Latest Posts

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    August 1, 2026

    AI in Formula One: Competitive advantage is all about the human in the loop

    August 1, 2026

    Pedro Sánchez hits out at EU leaders over criticism of Spain’s migrant crisis

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Ukrainian TV channel building hit by Russian drone as five killed in Kyiv

    September 8, 2026

    EU pursues closer Israel ties on air defense and space – POLITICO

    September 8, 2026

    Here in Liverpool, buses are back under public control – and that’s great for the only people who really matter | Steve Rotheram

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.