#EggJagger
Sality botnet takedown halts new malware, but EggJagger address‑swap remains active

https://newisty.com/blog/sality-botnet-takedown-halts-new-malware-but-eggjagger-addressswap-remains-active?utm_source=social&utm_campaign=crypto_ne
ws

#malware #crypto #security
September 8, 2026 at 7:24 PM
➤ However, installed malware, specifically the EggJagger tool, remains active and can still swap cryptocurrency addresses in the clipboard, potentially redirecting user payments.
September 8, 2026 at 4:00 PM
Sality botnet disrupted, but crypto-stealing malware remains
Sep 08 2026 14:35 UTC
The Sality botnet disruption blocked new payloads, CrowdStrike says, but installed crypto-address-swapping malware still needs removal.
#sality-botnet #cryptocurrency-theft #crowdstrike #eggjagger #malware
September 8, 2026 at 4:00 PM
➤ The botnet employed clipboard hijacking via the EggJagger malware to replace victim wallet addresses with fraudulent ones, stealing approximately $150,000 in crypto.
September 3, 2026 at 10:21 AM
Sality has been linked to cyberattacks and crypto theft since 2003, utilizing the EggJagger tool to exploit clipboard data for fraudulent gains.
September 2, 2026 at 9:48 PM
CrowdStrike turned Sality's own P2P network against itself to end SALTY SPIDER's run for good. https://intel.threadlinqs.com/threat/TL-2026-2303 #ThreatIntel #CVE_2017_0144 #Sality #EggJagger
September 3, 2026 at 1:35 AM
Global takedown hit Sality-linked infrastructure in the U.S. and Europe, with CrowdStrike and partners sinkholing super peers to disrupt P2P control channels used by SALTY SPIDER and EggJagger. #USA #Sality #CrowdStrike
Sality Botnet Infrastructure Dismantled In Joint Global Takedown
International law enforcement agencies and private partners seized Sality-linked infrastructure in the U.S. and Europe, while CrowdStrike helped dismantle the botnet’s peer-to-peer control channels. The operation disrupted more than two decades of activity tied to SALTY SPIDER and its use of Sality to spread EggJagger payloads in clipjacking attacks. #Sality #SALTYSPIDER #EggJagger #CrowdStrike #DOJ #FBI #DCIS
www.hendryadrian.com
September 2, 2026 at 9:00 AM
International law enforcement, in collaboration with CrowdStrike and Shadowserver Foundation, disrupted the Sality botnet, operational since 2003, which infected over 15,000 machines. The botnet primarily used EggJagger to steal cryptocurrency by replacing wallet addresses.
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
www.theregister.com
September 2, 2026 at 12:44 PM
September 2, 2026 at 8:45 AM
CrowdStrike and law enforcement disrupted the Sality P2P botnet, isolating infected machines and cutting off malware distribution after 20+ years. Over 15,000 systems were used for EggJagger, DDoS, and other payloads. #Sality #CrowdStrike #FBI
Peer Pressure: Inside The Sality Botnet Disruption Operation
CrowdStrike and international law enforcement disrupted the Sality P2P botnet, isolating infected machines and cutting off its ability to distribute payloads after more than two decades of operation. Sality had infected over 15,000 machines worldwide and was used to spread EggJagger, DDoS payloads, and other malware families for financial gain and...
www.hendryadrian.com
September 2, 2026 at 9:15 AM
23年間稼働し続けたボットネット、15,000超のエンドポイントを擁するも法執行機関とCrowdStrikeによりついに閉鎖

CrowdStrikeと法執行機関が、2003年から活動していたピアツーピア型ボットネットSalityを摘発ボットネットはマルウェアとクリップボードハイジャッカーEggJaggerを拡散し、15万ドル相当の暗号資産を窃取作戦ではエンドポイントをシンクホール化しペイロードURLを除去、DOJ、FBI、Europol
23年間稼働し続けたボットネット、15,000超のエンドポイントを擁するも法執行機関とCrowdStrikeによりついに閉鎖
CrowdStrikeと法執行機関が、2003年から活動していたピアツーピア型ボットネットSalityを摘発ボットネットはマルウェアとクリップボードハイジャッカーEggJaggerを拡散し、15万ドル相当の暗号資産を窃取作戦ではエンドポイントをシンクホール化しペイロードURLを除去、DOJ、FBI、Europol
blackhatnews.tokyo
September 2, 2026 at 2:40 PM
A decades-old botnet just got sinkholed live on stage as CrowdStrike poisoned its own peer list. https://intel.threadlinqs.com/threat/TL-2026-2284 #ThreatIntel #Sality #EggJagger #CrowdStrike
September 2, 2026 at 2:13 AM