
CrowdStrike warns that local malware on infected devices remains active despite the disruption of the botnet's command infrastructure.
AI-generated summary
Sality is a file-infecting botnet that has been active for years, primarily used to distribute malicious payloads like the EggJagger cryptocurrency address swapper.
The Aug. 31 disruption of the Sality botnet cut off its operator's ability to deliver new malicious software to infected computers, while malware already on those devices remained active, according to CrowdStrike's Sept. 1 report. Users of infected machines still need to remove the installed malware, including a tool that swaps cryptocurrency addresses and can redirect payments.
CrowdStrike said the botnet enabled payload distribution to more than 33,000 infected machines worldwide. The figure measures compromised computers; the number of users who lost cryptocurrency remains unspecified.
The Justice Department announced the multinational operation on Sept. 1, 2026, following the action the previous day. U.S. authorities seized Sality-linked domains, while partners in Bulgaria, Hungary and Romania acted against additional domains.
How the payment risk survives
CrowdStrike identified EggJagger as Sality's primary payload over the preceding eight years. The tool watches the clipboard for cryptocurrency addresses and substitutes ones controlled by the operator, including when someone copies a Bitcoin or Ethereum address for a payment.
The dangerous step is sending to the substituted address. A user can intend to pay the correct recipient yet paste a different destination into the payment form. The redirection takes effect if the user sends funds to that destination.
Address-swapping software already installed on a computer can keep operating after Sality's communications are cut off. Users with a confirmed infection therefore still need to have the malware removed from their devices.
CrowdStrike describes Sality as a file infector: it attaches to executable files and spreads through network shares, removable drives and file sharing. Those infected files are a separate problem from the network connections disrupted by the operation.
The disruption changed the lists of peers that infected machines use to communicate, isolating them from the operator and inserting defender-controlled servers known as sinkholes. CrowdStrike said isolated bots could no longer receive payload download instructions or direct transfers of malicious files. Partners also took down URLs hosting payloads.
For network operators, CrowdStrike recommends checking network logs and device telemetry for UDP traffic to its lighthouse address, 188.166.101[.]148. The company says a match indicates a Sality infection requiring remediation. Its technical report also provides YARA detection rules for scanning running processes.
The Justice Department said the Shadowserver Foundation is working with internet service providers and computer security incident response teams to identify infections and help notify affected users and support remediation.
For users of infected computers, remediation addresses the malware that can still replace a copied payment address. The botnet disruption alone leaves that local threat in place.
AI outlook — possibilities, not facts
Continued remediation efforts by Shadowserver and ISPs to notify infected users.
Very likely · Within weeks

The Ethereum Foundation's Protocol cluster has declined EIP-8363 for the Hegotá upgrade, calling for a broader ecosystem process to address validator issuance rewards and holder dilution.

Cardano's Leios scaling upgrade achieved a sixfold throughput increase in its first public testnet, but long-term staking economics still depend on driving sufficient fee-paying user adoption as reserve contributions decline.

A September 5 proposal to modify Ethereum's EIP-8141 would allow some nodes to accept privacy transactions above a 100,000-gas validation limit, but benchmark data shows required proof verification costs exceed this limit, raising concerns about network-wide support for private transactions like Tornado Cash and RAILGUN.

The Ethereum Foundation identified EIP-7805 (FOCIL) and EIP-8141 (Frame Transactions) as two 'must ship' proposals for the Hegotá upgrade, prioritizing censorship resistance and flexible account authentication.

Harmony blockchain plans to shut down its network on Sunday, citing escalating threats from AI agents and state actors, and proposes migrating its ONE token to Ethereum while launching an AI video initiative called 'The Remix Economy for AI Video'.

Ethereum co-founder Vitalik Buterin dismissed predictions that AI could cause a 50% Bitcoin crash within two years, arguing Bitcoin can withstand security failures not requiring social consensus and that AI-driven exploits are likely fixable. He contrasted with AI-risk commentator Liron Shapiro, who sees a 50% probability of such a crash due to AI undermining confidence in Bitcoin's security. The debate highlights growing concerns over AI's impact on crypto infrastructure, citing real-world examples like AI-assisted attacks on Bitcoin swap provider Boltz and industry-wide defensive initiatives involving Anthropic, Google, Microsoft, and JPMorgan Chase.