
15-Year-Old Sality Worm's TLS Fingerprint Ties to Tofsee C2
A Sality/badcrypt sample first seen in 2010 and still resubmitted through October 2025 shares a JA3 TLS fingerprint with spam botnet Tofsee. The overlap, plus a clipper-family tag, suggests an old worm chassis is being repurposed as delivery plumbing for cryptocurrency theft rather than reinvented.
A Windows binary that first surfaced in mid-2010 is still being resubmitted for scanning as recently as October 2025, and its TLS behaviour trips a crowdsourced intrusion-detection rule built for an entirely different malware family. The sample is labelled trojan.sality/badcrypt and flagged by 57 of 76 engines, placing it squarely in the Sality file-infector lineage — an old, well-understood worm chassis.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read