Sality is a long-running polymorphic Windows file-infector that evolved into a decentralized peer-to-peer botnet. First observed in 2003, it infects and modifies executable files and propagates when compromised executables are transferred through network shares, removable media, and file-sharing mechanisms. Its peer-to-peer architecture uses infected systems, including publicly reachable super peers, to relay commands and payload-delivery information without dependence on a conventional centralized command-and-control server.
Sality principally functioned as a malware-delivery platform. Payloads distributed through the botnet have supported credential theft, spam distribution, proxy services, network exploitation, distributed denial-of-service attacks, and cryptocurrency theft. For approximately eight years before its 2026 disruption, its principal payload was EggJagger, a clipboard-hijacking cryptocurrency clipper that substitutes copied wallet addresses to divert payments. CrowdStrike tracks the alleged financially motivated operator as SALTY SPIDER and assesses it likely operates from Russia's Republic of Bashkortostan; no public legal attribution or operator identity has been established.
In August 2026, an international operation used peer-list manipulation and defender-controlled sinkholes to isolate infected devices from the operator and prevent new commands and payloads from reaching them. Domain seizures also disrupted payload-hosting infrastructure. Sinkholing did not remove Sality or previously delivered payloads from compromised endpoints; affected systems require investigation and remediation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dragos researchers determined it did not crack the password at all, rather, it exploited a vulnerability in the firmware which allowed it to retrieve the password on command... This vulnerability was assigned CVE-2022-2003 and was responsibly disclosed to Automation Direct. They have released a firmware update to fix this issue. | the software was a malware dropper, infecting the machine with the Sality malware and turning the host into a peer in Sality’s peer-to-peer botnet.
The worm exploits the CVE-2010-2568 vulnerability... When a user tries to open an infected USB flash drive with an application that can display icons for shortcuts, the file with the name ~WTR4141.TMP is loaded and its entry point is called. | A number of new malware families were identified using same vulnerability in late July, and a number of other families such as Win32/Sality generated new variants that also used it.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SALTY SPIDER develops and maintains a botnet known as Sality that is a polymorphic file infector linked to an advanced peer-to-peer (P2P) botnet. The original centralized version of Sality goes back to at least 2003.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Sality also spread by attaching itself to executable files and moving through network shares, removable drives, and file-sharing systems.
It attached malicious code to executable files and could spread through network shares, removable drives and file-sharing systems.
Seized domains “had served as fallback infrastructure that infected systems could have used to fetch new malicious payloads even after the botnet’s core communication network was severed.”
La section « TTPs et IOCs détectés » liste « T1071.001 — Application Layer Protocol: Web Protocols (Command and Control) ».
During its long history, Sality distributed malware associated with credential theft, spam, proxy services, network exploitation and distributed denial-of-service attacks.
La section « TTPs et IOCs détectés » liste « T1090.001 — Proxy: Internal Proxy (Command and Control) ».
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A decentralized peer-to-peer botnet whose infected devices communicate directly using trusted-peer lists rather than a central command-and-control server. It was used to distribute payloads supporting cryptocurrency theft, spam, network exploitation, and distributed denial-of-service attacks. The disruption severed operator communications with more than 33,000 infected devices, but did not remove the malware or any delivered secondary payloads from endpoints.
A long-running peer-to-peer botnet that infects executable files and propagates through network shares, removable drives, and file-sharing systems. Its decentralized architecture used unauthenticated super peers and was disrupted through defender-controlled peer-list manipulation and sinkholing. It was used to distribute secondary malware and occasionally conduct DDoS attacks.
The referenced item concerns an international cyber takedown targeting Sality malware.
A long-running polymorphic file-infecting malware family and peer-to-peer botnet. It infects executable files and spreads via network shares, removable drives, and file-sharing systems; its decentralized botnet infrastructure was primarily used to distribute secondary malicious payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.