Breaking
September 8, 2026

Crypto News | Active crypto address “copy and paste attack” threatens users even after major malware cleanup cut off hackers Liam ‘Akiba’ Wright | usagoldmines.com

The Aug. 31 disruption of the Sality botnet cut off its operator’s ability to deliver new malicious software to infected computers, while malware already on those devices remained active, according to CrowdStrike’s Sept. 1 report. Users of infected machines still need to remove the installed malware, including a tool that swaps cryptocurrency addresses and can redirect payments.

CrowdStrike said the botnet enabled payload distribution to more than 33,000 infected machines worldwide. The figure measures compromised computers; the number of users who lost cryptocurrency remains unspecified.

The Justice Department announced the multinational operation on Sept. 1, 2026, following the action the previous day. U.S. authorities seized Sality-linked domains, while partners in Bulgaria, Hungary and Romania acted against additional domains.

How the payment risk survives

CrowdStrike identified EggJagger as Sality’s primary payload over the preceding eight years. The tool watches the clipboard for cryptocurrency addresses and substitutes ones controlled by the operator, including when someone copies a Bitcoin or Ethereum address for a payment.

The dangerous step is sending to the substituted address. A user can intend to pay the correct recipient yet paste a different destination into the payment form. The redirection takes effect if the user sends funds to that destination.

Related Reading

CryptoBandits malware lets criminals use your USB drive to access crypto wallets – Microsoft warns


Address-swapping software already installed on a computer can keep operating after Sality’s communications are cut off. Users with a confirmed infection therefore still need to have the malware removed from their devices.

Sality disruption on Aug. 31, 2026 blocked new payload delivery, while installed EggJagger can swap copied payment addresses. The flow shows payment redirection if the user sends to the substituted address, followed by detection and malware removal.

CrowdStrike describes Sality as a file infector: it attaches to executable files and spreads through network shares, removable drives and file sharing. Those infected files are a separate problem from the network connections disrupted by the operation.

The disruption changed the lists of peers that infected machines use to communicate, isolating them from the operator and inserting defender-controlled servers known as sinkholes. CrowdStrike said isolated bots could no longer receive payload download instructions or direct transfers of malicious files. Partners also took down URLs hosting payloads.

For network operators, CrowdStrike recommends checking network logs and device telemetry for UDP traffic to its lighthouse address, 188.166.101[.]148. The company says a match indicates a Sality infection requiring remediation. Its technical report also provides YARA detection rules for scanning running processes.

Related Reading

40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools


The Justice Department said the Shadowserver Foundation is working with internet service providers and computer security incident response teams to identify infections and help notify affected users and support remediation.

For users of infected computers, remediation addresses the malware that can still replace a copied payment address. The botnet disruption alone leaves that local threat in place.

Related Reading

Spot the crypto scam before you hit send


The post Active crypto address “copy and paste attack” threatens users even after major malware cleanup cut off hackers appeared first on CryptoSlate.

 CrowdStrike says the Aug. 31 disruption blocked new payload delivery while installed malware can still swap cryptocurrency payment addresses.
The post Active crypto address “copy and paste attack” threatens users even after major malware cleanup cut off hackers appeared first on CryptoSlate. Crime, Featured, Payments, Bitcoin, BTC, CrowdStrike, ETH, ethereum, payments 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.