APTMembers
APT

Salty Spider Hides Espionage Tool in Decade-Old Adware Bundle

A trojanised iMesh installer is delivering the Cydoor and SaveNow adware families to education and research institutions in France, the UK, and New Caledonia. The campaign, attributed to Salty Spider, wraps legacy adware in Armadillo and PEiD packing with active debugger detection — returning clean sandbox verdicts despite high static detection rates.

May 31, 2026, 17:24 (UTC+9)Last seenJun 1, 2026Severity72ByCTX TeamActorSalty SpiderKuKuIOC24MITRE43RegionsFRGBNC

A 2.3-megabyte Windows executable bearing "iMesh Inc" copyright metadata is circulating as what appears to be a routine peer-to-peer client installer — but the binary, tracked by CTX Team as iMeshV22.exe, bundles the Cydoor and SaveNow adware families inside a delivery chain that combines PEiD and Armadillo packing, active debugger detection, and a version-check beacon that registers each new victim with encoded telemetry.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence