FILEMembers
FILE

Salty Spider Pairs 7-Year Loader With Fresh Phorpiex Worm to Hit Transport

A freshly compiled Phorpiex worm variant and a long-running MSIL/AgentB trojan disguised as a USB Cleaner utility are circulating together in an active campaign targeting transportation organisations. The loader defeats dynamic sandbox analysis with a 97-confidence clean verdict despite 48 of 76 antivirus engines flagging it as malicious, while C2 traffic routes to a Seychelles-incorporated bulletproof host already listed on Spamhaus DROP group 33.

Jun 9, 2026, 00:37 (UTC+9)Last seenJun 9, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC4MITRE25

##A Seven-Year Loader Meets a Zero-Day Worm: Salty Spider's Layered Evasion Campaign Targets Transportation A freshly compiled Phorpiex worm variant — PE timestamp matching its first submission date of 2026-02-09, zero prior detection history at the moment of deployment — is circulating alongside a seven-year-old MSIL/AgentB trojan that successfully convinces automated sandbox analysis it is harmless, even as 48 of 76 antivirus engines flag it as malicious. The pairing is not accidental.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence