Active crypto address “copy and paste attack” threatens users even after major malware cleanup cut off hackers

The Aug. 31 disruption of the Sality botnet cut off its operator's ability to deliver new malicious software to infected computers, while malware already on those devices remained active, according to CrowdStrike's Sept. 1 report. Users of infected machines still need to remove the installed malware, including a tool that swaps cryptocurrency addresses and can redirect payments.
CrowdStrike said the botnet enabled payload distribution to more than 33,000 infected machines worldwide. The figure measures compromised computers; the number of users who lost cryptocurrency remains unspecified.
The Justice Department announced the multinational operation on Sept. 1, 2026, following the action the previous day. U.S. authorities seized Sality-linked domains, while partners in Bulgaria, Hungary and Romania acted against additional domains.
How the payment risk survives
CrowdStrike identified EggJagger as Sality's primary payload over the preceding eight years. The tool watches the clipboard for cryptocurrency addresses and substitutes ones controlled by the operator, including when someone copies a Bitcoin or Ethereum address for a payment.
… Continue reading the full article at the original source below.



