SALTY SPIDER is a financially motivated Russian cybercrime group assessed to operate from the Republic of Bashkortostan, Russia. It develops and operates Sality, a long-running polymorphic file-infector that evolved into a peer-to-peer botnet and malware-delivery platform. SALTY SPIDER is also associated with the community identifiers Kukacka, KuKu, SalLoad, Kookoo, and SaliCode. Sality propagated through infected executable files, network shares, removable media, and file-sharing systems. The botnet has distributed payloads supporting credential theft, spam delivery, proxy services, network exploitation, and distributed denial-of-service attacks. In its later operations, its principal payload was EggJagger, a cryptocurrency clipboard hijacker that substitutes copied cryptocurrency wallet addresses to divert payments. The actor has conducted financially motivated activity against cryptocurrency-related services and has also used Sality-delivered DDoS payloads against targets in Ukraine and Russia. In August 2026, an international law-enforcement and private-sector operation disrupted Sality’s peer-to-peer control infrastructure and prevented the operator from issuing new commands or delivering further payloads; previously compromised systems and payloads still require remediation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operator of the Sality peer-to-peer botnet, used to distribute secondary malicious payloads, including credential theft, spam, proxy, network-exploitation, DDoS, and cryptocurrency clipboard-hijacking malware. Its active command channel and peer network were disrupted through domain seizures and P2P sinkholing in August 2026.
Operators of the long-running Sality P2P botnet, used to distribute malware including credential stealers and the EggJagger cryptocurrency clipboard hijacker, send spam, provide proxy services, and conduct cyberattacks and DDoS activity.
Operated the long-running Sality peer-to-peer botnet, distributing payloads for cryptocurrency theft, credential theft, spam distribution, proxy services, network intrusion, and denial-of-service attacks. Its primary recent payload, EggJagger, replaces copied cryptocurrency wallet addresses in victims' clipboards with attacker-controlled addresses.
Operated the Sality P2P botnet for more than two decades. The botnet distributed EggJagger through clipjacking attacks and has historically been used to distribute credential-stealing malware and spam, provide proxy services, exploit networks, and conduct DDoS attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.