Sality botnet disrupted, but EggJagger clipboard malware persists on infected devices

Editorial illustration: A transparent computer contains a clipboard and conveyor carrying cream-colored blocks. A red branch curves toward a dark red wallet, while a metal barrier blocks an overhead chute of black shapes.

In brief

  • Aug. 31 operation severed Sality's command-and-control infrastructure, blocking new malware delivery
  • EggJagger malware swaps cryptocurrency addresses from clipboard, redirecting payments to attacker wallets
  • Justice Department announced multinational operation involving U.S., Bulgaria, Hungary, Romania
  • CrowdStrike recommends scanning logs for UDP traffic to detect lingering Sality infections

The disruption and its limits

The Aug. 31 operation cut off the botnet's operator's ability to deliver new payloads to infected machines, but malware already installed on those devices remained active. The disruption worked by changing the peer lists that infected machines use to communicate, isolating them from their operator and inserting defender-controlled servers (sinkholes) into the network.

The Justice Department announced the multinational operation on Sept. 1, 2026, following the action the previous day. U.S. authorities seized Sality-linked domains, while partners in Bulgaria, Hungary and Romania acted against additional domains.

The persistent threat

CrowdStrike identified EggJagger as Sality's primary payload over the preceding eight years. The tool watches the clipboard for cryptocurrency addresses and substitutes ones controlled by the operator. A user can intend to pay the correct recipient yet paste a different destination into the payment form. Once the address swap occurs, the transaction is irreversible.

The botnet enabled payload distribution to more than 33,000 infected machines worldwide. CrowdStrike describes Sality as a file infector that attaches to executable files and spreads through network shares, removable drives and file sharing.

What users and operators should do

"Users of infected machines still need to remove the installed malware, including a tool that swaps cryptocurrency addresses and can redirect payments." — CrowdStrike report

CrowdStrike recommends checking network logs and device telemetry for UDP traffic to lighthouse address 188.166.101.148 to identify Sality infections. The Shadowserver Foundation is working with internet service providers and computer security incident response teams to identify infections and help notify affected users.

The disruption didn't eliminate the risk. It simply stopped new infections. Existing victims need active remediation to purge EggJagger and prevent ongoing fund theft.