APTMembers
APT

15-Year-Old Sality Worm Still Feeding Cryptomining Campaigns in 2025

A Sality worm sample first seen in 2010 was still circulating in October 2025, now surfacing alongside XMRig-derived miners disguised as Windows processes, extension-spoofed staging files, and DNS-over-HTTPS beaconing. No shared imphash, signer, or certificate links the pieces — pointing to opportunistic reuse rather than a single engineered operation.

Jul 26, 2026, 21:34 (UTC+9)Last seenJul 26, 2026Severity87ByCTX TeamActorSalty SpiderKuKuIOC59MITRE51RegionsUS

A sample of the Sality worm first submitted for scanning in July 2010 was still circulating as recently as October 2025 — 281 submissions from 46 unique sources over fifteen years, according to detection telemetry reviewed by CTX Team. That file, still tagged with the classic markers of a USB-borne spreader, is now turning up alongside modern XMRig-derived cryptomining binaries dressed up as core Windows processes, extension-spoofed staging pages, and DNS-over-HTTPS beaconing.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence