
15-Year-Old Sality Worm Still Feeding Cryptomining Campaigns in 2025
A Sality worm sample first seen in 2010 was still circulating in October 2025, now surfacing alongside XMRig-derived miners disguised as Windows processes, extension-spoofed staging files, and DNS-over-HTTPS beaconing. No shared imphash, signer, or certificate links the pieces — pointing to opportunistic reuse rather than a single engineered operation.
A sample of the Sality worm first submitted for scanning in July 2010 was still circulating as recently as October 2025 — 281 submissions from 46 unique sources over fifteen years, according to detection telemetry reviewed by CTX Team. That file, still tagged with the classic markers of a USB-borne spreader, is now turning up alongside modern XMRig-derived cryptomining binaries dressed up as core Windows processes, extension-spoofed staging pages, and DNS-over-HTTPS beaconing.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read