C&CMembers
C&C

Sality Botnet Still Active After 15 Years, Adds Zero-Detection Payload

A Sality polymorphic file-infector attributed to Salty Spider continues beaconing across two C2 domains using a fingerprint-ready URL scheme. A trojanised Microsoft redistributable and a freshly staged, undetected JSON-masquerading executable reveal an operator quietly refreshing evasion while leaving aged infrastructure intact.

Jun 4, 2026, 07:38 (UTC+9)Last seenJun 4, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC54RegionsCM

Fourteen distinct HTTP beacon paths. Two C2 domains. A core sample that has been resubmitted to threat intelligence platforms continuously from July 2010 through October 2025. And, sitting at the edge of this campaign, a file submitted just days before this analysis — typed as JSON, carrying zero detections across 76 engines, with an alternate name pointing to a randomised executable path buried deep inside Program Files. The Sality polymorphic file-infector is not a relic.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence