Sality Botnet Malware Still Active After Disruption
A recent operation against the Sality botnet has left users of infected computers at risk of losing cryptocurrency due to malware that can swap payment addresses.
CrowdStrike reports that the disruption on August 31 blocked new malicious payloads from being delivered, but installed malware remains active and can still substitute cryptocurrency addresses with ones controlled by its operator.
The malware, known as EggJagger, watches the clipboard for cryptocurrency addresses and substitutes them with others under the control of the operator. This can result in users sending funds to the wrong destination even if they intend to pay the correct recipient.
According to CrowdStrike, over 33,000 infected machines worldwide were affected by the Sality botnet, which enabled payload distribution through network shares, removable drives, and file sharing.