C&CMembers
C&C

Sality Botnet Hides C2 Traffic in GIF Requests Across Italian and Polish Hosts

A Sality cluster attributed to Salty Spider is routing encrypted bot check-ins through parameterised image fetch requests to compromised shared-hosting accounts in Italy and Poland. The campaign pairs a polymorphic USB-spreading file-infector with a GIF-based beaconing channel that passes every antivirus engine, generating active C2 traffic into mid-2026 from a core payload first seen in July 2010.

Jun 17, 2026, 08:03 (UTC+9)Last seenJun 17, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC52RegionsBD

Twenty-four HTTP GET requests. Two geographically disparate web servers. One 5-kilobyte image file. On the surface, a routine web browser fetching a logo. Underneath, an active Sality botnet cluster routing encrypted bot check-ins through parameterised image requests to compromised shared-hosting accounts in Italy and Poland — a beaconing architecture that has been generating fresh C2 traffic into mid-2026 from a core payload first submitted to VirusTotal in July 2010.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence