The Sality botnet's takedown stopped new malware from spreading but left existing infections active on over 33000 computers worldwide, allowing address-swapping tools to keep hijacking copied crypto payment details and putting user funds at risk
Cutting off the Sality botnet's command infrastructure may have stopped new malware from reaching fresh victims, but for thousands of crypto users, the threat is far from over. Devices already infected with Sality's address-swapping malware remain compromised, silently redirecting copied Bitcoin and Ethereum payment details to attacker-controlled wallets. The U.S. Department of Justice's recent multinational operation may have disrupted the botnet's global reach, but it did not neutralize the malware still lurking on compromised machines.
Malware Lingers After Network Disruption
According to a report from CrowdStrike, the Sality botnet had enabled the distribution of malicious payloads to more than 33,000 computers worldwide before its disruption on August 31. While the operation-coordinated with authorities in Bulgaria, Hungary, and Romania-successfully seized Sality-linked domains and replaced operator-controlled servers with defender-controlled sinkholes, the malware already installed on user devices continues to operate independently. This means that even after the botnet's communications were severed, infected computers can still run clipboard-monitoring tools that swap out cryptocurrency addresses during copy-paste actions, putting any outgoing payments at risk of redirection.
How Address Swapping Works
The primary payload, identified as EggJagger, monitors the clipboard for strings resembling cryptocurrency addresses. When a user copies a Bitcoin or Ethereum address-often to make a payment-the malware instantly replaces it with an address controlled by the attacker. If the user fails to notice the substitution and proceeds with the transaction, funds are sent directly to the attacker's wallet. This attack vector is especially insidious because it exploits routine user behavior and can bypass even vigilant manual checks if the user is distracted or in a hurry.
Detection and Remediation Challenges
For network operators and individual users, identifying a Sality infection is not always straightforward. CrowdStrike recommends monitoring for UDP traffic to the IP address 188.166.101[.]148, which served as a lighthouse for infected devices. A match in network logs or device telemetry signals a likely infection and the need for immediate remediation. The Shadowserver Foundation is now working with ISPs and security response teams to help notify affected users and support cleanup efforts. Yet, the onus remains on users to remove the malware from their systems, as the botnet takedown alone does not eliminate the local threat.
Broader Security Implications
Address-swapping malware is not a new phenomenon, but the scale of Sality's reach and the persistence of its payloads highlight a critical gap in crypto user security. Unlike high-profile exchange hacks or smart contract exploits, clipboard hijacking targets individuals directly and can drain funds with little recourse. The number of users who have lost cryptocurrency due to Sality's address-swapping tool remains unreported, but the risk is ongoing for anyone operating an infected device. As reported earlier, attackers continue to exploit compromised wallets and cross-chain bridges, making vigilance and proactive device security essential for anyone transacting in digital assets.
CrowdStrike's technical report provides YARA detection rules for scanning running processes, and network operators are urged to check for suspicious peer lists and payload download attempts. URLs previously used to host malicious files have been taken down, but infected files can still spread through removable drives and file sharing, compounding the cleanup challenge.
Based on CrowdStrike's findings, the Sality botnet distributed malicious payloads to over 33,000 computers globally before its disruption on August 31, 2026. The U.S. Department of Justice announced the operation on September 1, 2026, following coordinated domain seizures and network interventions in multiple countries. The number of users who lost funds due to address-swapping malware remains unconfirmed, but the risk persists for any device that has not been fully cleaned.
Address-swapping attacks exploit a fundamental weakness in how most users handle cryptocurrency transactions: the reliance on copy-paste for wallet addresses. Because blockchain transactions are irreversible, a single unnoticed substitution can result in permanent loss of funds. Unlike phishing or exchange breaches, clipboard hijacking operates at the device level, often evading detection by antivirus tools and leaving users with little recourse once funds are sent. Regular device scans, careful address verification, and prompt remediation of known malware are essential defenses against this persistent threat.