
Decade-Old Sality Worm Feeds a Modern XMRig Cryptomining Chain
A CTX intake batch pairs a 2010-era Sality USB worm with a heavily-evaded XMRig miner, linked only by a Tofsee-associated TLS fingerprint and a templated certificate shared by two lookalike shopping domains. None of the seven files share an imphash, signer, or family label, suggesting a stitched-together monetization pipeline rather than one coordinated intrusion.
The oldest file in a cluster CTX Team pulled together this week first surfaced in 2010 — a self-propagating Sality-family dropper that still spreads over USB autorun and waits for a user to double-click it before running. Fifteen years later, the same intake batch contains a modern XMRig-derived cryptomining binary carrying nine named YARA detections and a dormancy routine that checks the CPU clock before it starts hijacking a victim's processor.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read