APTMembers
APT

Decade-Old Sality Worm Feeds a Modern XMRig Cryptomining Chain

A CTX intake batch pairs a 2010-era Sality USB worm with a heavily-evaded XMRig miner, linked only by a Tofsee-associated TLS fingerprint and a templated certificate shared by two lookalike shopping domains. None of the seven files share an imphash, signer, or family label, suggesting a stitched-together monetization pipeline rather than one coordinated intrusion.

Aug 22, 2026, 22:37 (UTC+9)Last seenAug 22, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC55MITRE15RegionsUS

The oldest file in a cluster CTX Team pulled together this week first surfaced in 2010 — a self-propagating Sality-family dropper that still spreads over USB autorun and waits for a user to double-click it before running. Fifteen years later, the same intake batch contains a modern XMRig-derived cryptomining binary carrying nine named YARA detections and a dormancy routine that checks the CPU clock before it starts hijacking a victim's processor.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence