
Sality Botnet Hides C2 Traffic in GIF Requests Across Italian and Polish Hosts
A Sality cluster attributed to Salty Spider is routing encrypted bot check-ins through parameterised image fetch requests to compromised shared-hosting accounts in Italy and Poland. The campaign pairs a polymorphic USB-spreading file-infector with a GIF-based beaconing channel that passes every antivirus engine, generating active C2 traffic into mid-2026 from a core payload first seen in July 2010.
Twenty-four HTTP GET requests. Two geographically disparate web servers. One 5-kilobyte image file. On the surface, a routine web browser fetching a logo. Underneath, an active Sality botnet cluster routing encrypted bot check-ins through parameterised image requests to compromised shared-hosting accounts in Italy and Poland — a beaconing architecture that has been generating fresh C2 traffic into mid-2026 from a core payload first submitted to VirusTotal in July 2010.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read