APTMembers
APT

Sality-Linked Miner Cluster Shares Temp Staging, Not Build Code

Six file indicators tagged to Salty Spider/Sality show two build-unrelated XMRig miners staged through identical randomized hex Temp folders. A Romanian ISP node's TLS certificate impersonates Akamai's edge identity, but the tradecraft pattern matters more than the actor label attached to it.

Jul 7, 2026, 10:44 (UTC+9)Last seenJul 7, 2026Severity87ByCTX TeamActorSalty SpiderKuKuIOC10MITRE32RegionsUS

Two XMRig-derived cryptomining binaries flagged in the same indicator set carry the identical classification tokens "malxmr" and "smcgr26" — yet their import-table hashes and vhash fingerprints have nothing in common, meaning they were never compiled from the same source tree. What does tie the cluster together is a staging habit: a config file, a miner executable, and an unidentified data blob all drop into randomized six-character hex subfolders inside %TEMP%, a loader convention that…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence