Sality is a long-running Windows malware family first observed in 2003 that evolved from a polymorphic executable-file infector into a decentralized peer-to-peer botnet and payload-distribution platform. It infects Windows executable files, propagates through removable media and network shares, and incorporates compromised systems into P2P networks that distribute commands, payload-download instructions, and direct payload transfers without relying on conventional centralized command-and-control infrastructure. Sality has used process injection, rootkit drivers, security-product termination, security-update blocking, registry modification, and Safe Mode disruption to persist and evade defenses. Historical variants also included keylogging, credential theft, data theft, spam relaying, proxying, and the ability to download and execute additional malware. Sality infrastructure has distributed DDoS payloads and, in its later activity, primarily delivered EggJagger, a cryptocurrency clipboard-hijacking payload. CrowdStrike tracks the alleged operator as SALTY SPIDER, assessed as likely Russia-based. A multinational sinkholing and infrastructure-seizure operation in August 2026 disrupted the botnet’s operator control and ability to deliver further payloads; compromised hosts and payloads already installed on them still require remediation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dragos researchers determined it did not crack the password at all, rather, it exploited a vulnerability in the firmware which allowed it to retrieve the password on command... This vulnerability was assigned CVE-2022-2003 and was responsibly disclosed to Automation Direct. They have released a firmware update to fix this issue. | the software was a malware dropper, infecting the machine with the Sality malware and turning the host into a peer in Sality’s peer-to-peer botnet.
The worm exploits the CVE-2010-2568 vulnerability... When a user tries to open an infected USB flash drive with an application that can display icons for shortcuts, the file with the name ~WTR4141.TMP is loaded and its entry point is called. | A number of new malware families were identified using same vulnerability in late July, and a number of other families such as Win32/Sality generated new variants that also used it.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
It has been distributed through various methods, including infected network shares, USB devices, file sharing, compromised websites, email attachments, and peer-to-peer (P2P) networks.
...it has advanced features like a peer-to-peer botnet, a rootkit which is able to kill AVs...
Sality employs polymorphic and entry-point obscuring (EPO) techniques to infect files... The code at the entry-point is changed, and replaced by a variable stub, generated by Sality polymorphic code generator... The initial code of this body is also polymorphic and contains junk instructions to thwart emulation strategies used by anti-virus.
It abuses Window’s autorun functionality to spread copies of itself over Universal Serial Bus (USB), network shares, and external storage drives.
the software was a malware dropper, infecting the machine with the Sality malware and turning the host into a peer in Sality’s peer-to-peer botnet.
Sality did not rely on a central command-and-control (C&C) server for receiving code updates... infected machines forming the backbone of the P2P network.
Sality дистрибуирал ... [малвер] наменет за ... експлоатација на мрежи.
Although Sality's operations are primarily driven by financial gain, the malware has been used to conduct three notable DDoS attack campaigns.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A long-running file-infecting malware family evolved into two incompatible P2P botnet networks (versions 3 and 4). It spread through infected executable files copied via network shares, USB drives, and file-sharing networks, and was used to distribute payloads for credential theft, spam, proxy services, network exploitation, DDoS attacks, and, most recently, the EggJagger cryptocurrency clipboard hijacker.
A long-running peer-to-peer botnet used to distribute payloads. Historically it has supported credential theft, spam distribution, proxy services, network exploitation, and DDoS attacks. Its control infrastructure was disrupted through domain seizures and P2P sinkholing.
A peer-to-peer botnet and file-infector malware that attaches to executables on disk and removable media. Its decentralized peer network distributed payloads including information stealers, proxy services, DDoS payloads, and EggJagger. The botnet was disrupted through peer-list manipulation, sinkholing, and payload-URL takedowns.
A long-running peer-to-peer botnet used to distribute malicious payloads. The content states it had operated for more than two decades and was linked to more than 11 million infected IP addresses worldwide.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.