
Salty Spider Hides Espionage Tool in Decade-Old Adware Bundle
A trojanised iMesh installer is delivering the Cydoor and SaveNow adware families to education and research institutions in France, the UK, and New Caledonia. The campaign, attributed to Salty Spider, wraps legacy adware in Armadillo and PEiD packing with active debugger detection — returning clean sandbox verdicts despite high static detection rates.
A 2.3-megabyte Windows executable bearing "iMesh Inc" copyright metadata is circulating as what appears to be a routine peer-to-peer client installer — but the binary, tracked by CTX Team as iMeshV22.exe, bundles the Cydoor and SaveNow adware families inside a delivery chain that combines PEiD and Armadillo packing, active debugger detection, and a version-check beacon that registers each new victim with encoded telemetry.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read