Sality is a long-running malware family and botnet best known as a polymorphic file-infector that also functions as a distributed malware delivery and remote-control platform. In addition to infecting executable files and spreading across removable and network-accessible media, Sality has been used to conscript compromised systems into a botnet for follow-on malicious activity. Reported activity includes deployment via third-party tooling, including software used to compromise industrial environments, where infected hosts were joined to the Sality botnet. Sality is generally associated with cybercriminal operations rather than a named nation-state actor. Its observed behavior supports use for initial compromise support, persistence, post-compromise control, and malware distribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.