Security researchers disrupted the long-running Sality botnet, but they warn that many infected computers may still swap copied cryptocurrency addresses for ones controlled by criminals. The Sality botnet disruption stopped new instructions from reaching those machines, yet the malware already installed on them keeps running until someone removes it.
Sality is a piece of malware first seen in 2003 that spreads by infecting programs, including files shared over networks or copied to removable drives, according to CrowdStrike. Security firm CrowdStrike said it ran the coordinated takedown on August 31, 2026, with law-enforcement and industry partners. For related coverage, see Polish Crypto Firms Lack a Domestic EU Licensing Route.
The operation drew on the U.S. Department of Justice, the FBI, the Defense Criminal Investigative Service, the Shadowserver Foundation, and European authorities. The Record, a cybersecurity news outlet, reported the same Monday operation and said no arrests were announced and the operator was not named. For related coverage, see PolyNext Awards & Conference Dubai 2026: Advancing the Global Dialogue on Plastic Recycling and Circularity.
What the Sality botnet disruption means for infected computers
A botnet is a network of hijacked computers controlled by attackers. Disrupting the botnet’s command network is not the same as cleaning each infected machine.
The takedown isolated bots by manipulating their peer lists and routing them to defender-controlled sinkholes, decoy servers that catch traffic. That blocked isolated machines from receiving new instructions or new malware, Decrypt reported.
But cutting off the network does not delete what is already there. CrowdStrike’s Counter Adversary Operations team was direct about the limit of the operation.
While the disruption prevents new payloads from reaching infected machines, existing malware already installed on those systems remains active and should be removed.
Source: CrowdStrike
So the risk is conditional. Not every previously infected computer keeps behaving badly, but the disruption alone does not prove any single machine is clean.
How copied crypto address replacement can put transfers at risk
For the past eight years, Sality mainly delivered a payload called EggJagger, CrowdStrike said. EggJagger watches the clipboard, the temporary storage that holds text you copy, and swaps copied crypto wallet addresses for attacker-controlled ones.
The primary report names copied Bitcoin and Ethereum payment addresses as the specific targets of this substitution. Crypto addresses are long strings that are hard to read, so most people copy and paste them rather than type them.
Here is the danger in plain terms. You copy a friend’s address, but the malware quietly pastes a different one. If you do not notice and you approve the transfer, the money goes to the attacker instead.
CrowdStrike estimates EggJagger stole at least 12.1 million rubles, roughly $150,000. That is an estimate for this one payload, not an audited total for all Sality activity, and not proof of any theft after the disruption.
CrowdStrike’s EggJagger theft estimate
At least ₽12.1 million
Importantly, a swapped address does not mean your wallet keys were stolen or a blockchain was hacked. The attacker only changes where a payment goes; the rest of your wallet stays as it was.
Reports differ on how many machines the operation touched. CrowdStrike’s page cites over 33,000 infected machines worldwide, while Decrypt and The Record cite more than 15,000; the reason for the gap is not established, so treat each figure as attributed and unreconciled.
What to check before sending crypto from a suspected infected computer
The practical takeaway is simple: check the destination address every time. This matters even more given that infected machines may still be swapping addresses.
Compare the whole pasted address against the recipient’s real address, obtained through a trusted channel like a phone call. Where possible, confirm it on a separate trusted screen, such as a hardware wallet display, before approving.
Careful destination checks echo the direction of regulators like the Banca d’Italia’s call for crypto transfer screening, which pushes firms to scrutinize where funds are actually going. The same habit protects individual users at the moment of sending.
If an address changes unexpectedly, or you suspect an infection, stop the transfer. Move sensitive wallet activity to a device you know is clean.
Shadowserver is working with internet providers and security response teams to find infected systems and notify their owners, The Record reported. David Watson, a director at Shadowserver, noted that compromised machines stay dangerous because they can still give attackers a foothold inside organizations.
Do not treat the disruption, or one successful address check, as proof your computer is clean. Seek reputable security guidance to inspect and remediate the machine. The stakes are familiar across crypto security incidents, from botnets to exchange breaches like the recent effort to recover thousands of BTC after a reserve drain, and from tightening oversight such as Australia’s removal of dozens of crypto registrations.
For a regular holder, the message is reassuring but requires action. The criminals lost their remote controls, yet the tools they left behind can still redirect a payment until the infected computer is cleaned.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.