
Sality Botnet Still Active After 15 Years, Adds Zero-Detection Payload
A Sality polymorphic file-infector attributed to Salty Spider continues beaconing across two C2 domains using a fingerprint-ready URL scheme. A trojanised Microsoft redistributable and a freshly staged, undetected JSON-masquerading executable reveal an operator quietly refreshing evasion while leaving aged infrastructure intact.
Fourteen distinct HTTP beacon paths. Two C2 domains. A core sample that has been resubmitted to threat intelligence platforms continuously from July 2010 through October 2025. And, sitting at the edge of this campaign, a file submitted just days before this analysis — typed as JSON, carrying zero detections across 76 engines, with an alternate name pointing to a randomised executable path buried deep inside Program Files. The Sality polymorphic file-infector is not a relic.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read