FILEMembers
FILE

15-Year-Old Sality Worm's TLS Fingerprint Ties to Tofsee C2

A Sality/badcrypt sample first seen in 2010 and still resubmitted through October 2025 shares a JA3 TLS fingerprint with spam botnet Tofsee. The overlap, plus a clipper-family tag, suggests an old worm chassis is being repurposed as delivery plumbing for cryptocurrency theft rather than reinvented.

Aug 12, 2026, 14:41 (UTC+9)Last seenAug 12, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC24MITRE32RegionsBD

A Windows binary that first surfaced in mid-2010 is still being resubmitted for scanning as recently as October 2025, and its TLS behaviour trips a crowdsourced intrusion-detection rule built for an entirely different malware family. The sample is labelled trojan.sality/badcrypt and flagged by 57 of 76 engines, placing it squarely in the Sality file-infector lineage — an old, well-understood worm chassis.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence