Malware

Sality

F-Secure states that the Sality virus family has been circulating in the wild as early as 2003. Over the years, the malware has been developed and improved with the addition of new features, such as rootkit or backdoor functionality, and so on, keeping it an active and relevant threat despite the relative age of the malware. Modern Sality variants also have the ability to communicate over a peer-to-peer (P2P) network, allowing an attacker to control a botnet of Sality-infected machines. The combined resources of the Sality botnet may also be used by its controller(s) to perform other malicious actions, such as attacking routers. Infection Sality viruses typically infect executable files on local, shared and removable drives. In earlier variants, the Sality virus simply added its own malicious code to the end of the infected (or host) file, a technique known as prepending. The viral code that Sality inserts is polymorphic, a form of complex code that is intended to make analysis more difficult. Earlier Sality variants were regarded as technically sophisticated in that they use an Entry Point Obscuration (EPO) technique to hide their presence on the system. This technique means that the virus inserts a command somewhere in the middle of an infected file's code, so that when the system is reading the file to execute it and comes to the command, it forces the system to 'jump' to the malware's code and execute that instead. This technique was used to make discovery and disinfection of the malicious code harder. Payload Once installed on the computer system, Sality viruses usually also execute a malicious payload. The specific actions performed depend on the specific variant in question, but generally Sality viruses will attempt to terminate processes, particularly those related to security programs. The virus may also attempt to open connections to remote sites, download and run additional malicious files, and steal data from the infected machine.

Indicators of Compromise 21

MITRE ATT&CK TTPs 5

Source Articles

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
Authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with CrowdStrike and the Shadowserver Foundation, disrupted the long-standing Sality peer-to-peer botnet on August 31, 2026. The operation used peer list manipulation to turn the botnet's P2P architecture against itself, sinkholing traffic and preventing infected machines from receiving new payloads. Sality, active since 2003, infects Windows executables and has delivered payloads like EggJagger, a clipper malware that steals cryptocurrency by replacing wallet addresses. While the disruption halts new payload delivery, existing infections remain active and require remediation.
hacker-news ·4h ago
Sality botnet infrastructure dismantled in joint global takedown
The Sality botnet, active for over two decades and responsible for infecting more than 15,000 devices, has been disrupted in a joint global takedown operation led by international law enforcement and private sector partners including Europol, FBI, and CrowdStrike. The botnet, attributed to the threat actor group SALTY SPIDER believed to be operating from Russia's Republic of Bashkortostan, used a peer-to-peer (P2P) architecture to distribute malware payloads, primarily EggJagger in recent years. EggJagger is a clipjacking tool that monitors and replaces cryptocurrency wallet addresses in the clipboard with attacker-controlled ones. The disruption was achieved by sinkholing the botnet’s super peer infrastructure, effectively severing communication between infected machines and preventing further propagation of malicious payloads.
bleeping-computer ·3h ago