A Windows virus from 2003 was still quietly earning money last week
Sality first appeared in 2003, back when Windows XP was new. On 31 August the US Department of Justice, working with police in Bulgaria, Hungary and Romania alongside CrowdStrike and the Shadowserver Foundation, finally cut its head off. They used the botnet's own design against it: Sality had no central server, so investigators quietly fed their own machines into its peer lists until the infected PCs were talking to nothing but sinkholes. Around 15,000 machines worldwide were still connected.
What it had been doing lately is the interesting bit. For the past eight years its main payload was a clipboard watcher called EggJagger. It sat there waiting for you to copy a cryptocurrency wallet address, swapped it for the attacker's address at the moment you pasted, and let you press send yourself. No alarm, no ransom note, just money going somewhere else.
Sality spread the old-fashioned way, and that is why it lasted so long. It attached itself to ordinary program files on a PC, then rode network shares and USB sticks to the next one. Plenty of the surviving infections sit on machines that were rebuilt years ago from a backup image that was already carrying it.
The takedown stops new instructions arriving. It does not clean anything, so the malware is still on those computers. If a PC in your house has been handed down between family members or restored from an old image, a full scan with Microsoft Defender or another antivirus is the right move this week. Tendvane isn't an antivirus and won't remove it, but its Safety check does surface programs and startup items you never chose to install, which is often the first hint something has been riding along.