SALTY SPIDER is a Russia-based cybercrime group assessed to develop and operate the long-running Sality peer-to-peer botnet. The group is likely based in the Republic of Bashkortostan, Russia. Sality has operated since at least 2003 and infected more than 15,000 devices. Its decentralized peer-to-peer architecture enabled distribution of direct payload packages and instructions for malware downloads. The botnet historically distributed malware supporting credential theft, spam operations, proxy services, network exploitation, and distributed denial-of-service attacks. In its later active period, Sality primarily delivered EggJagger, a cryptocurrency clipboard-hijacking payload that substitutes copied wallet addresses with attacker-controlled addresses. SALTY SPIDER's operations are primarily financially motivated, although Sality has also been used in DDoS campaigns, including activity against Ukrainian and Russian targets. International law-enforcement and private-sector partners disrupted Sality by sinkholing its peer-to-peer communications infrastructure and preventing operators from issuing new tasking or distributing new payloads; malware and payloads already installed on compromised endpoints required separate remediation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operated the Sality P2P botnet for more than two decades. The botnet distributed EggJagger through clipjacking attacks and has historically been used to distribute credential-stealing malware and spam, provide proxy services, exploit networks, and conduct DDoS attacks.
Operated the Sality peer-to-peer botnet, which was disrupted through a coordinated law-enforcement domain seizure and sinkhole operation. The active botnet networks were primarily used to distribute EggJagger payloads for cryptocurrency-address clipjacking.
Named threat actor referenced in global threat reporting.
Russian cybercriminal group highlighted in the alert as part of the broader Russian cyber threat landscape.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.