Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 3 IP / 12 hostnames
Sality is a long-running Windows malware family first observed in 2003.
Profile source: Mallory opens in a new tabSality
Sality is a long-running Windows malware family first observed in 2003. It is a polymorphic executable-file infector that evolved into a decentralized peer-to-peer botnet and malware-delivery platform. It infects Windows executables, propagates through network shares and removable storage, and enrolls compromised hosts into a custom P2P network that distributes signed payload instructions and, in later variants, payload files directly.
Sality incorporates substantial defense-evasion and persistence functionality, including process injection, security-product termination, interference with security updates and resources, Windows security-configuration tampering, and kernel-level components in some variants. Historical variants also performed keylogging, credential theft, and data exfiltration. The botnet has delivered spam relays, proxy components, information stealers, web compromise tooling, distributed password-cracking payloads, and DDoS payloads.
A major long-term payload family delivered through Sality was EggJagger, which hijacked cryptocurrency wallet addresses copied to the clipboard to redirect payments to attacker-controlled wallets. Sality operations have primarily been assessed as financially motivated, although the botnet has also been used in DDoS campaigns with apparent politically aligned and personal-grievance motivations. CrowdStrike tracks activity associated with Sality under the SALTY SPIDER designation. International law-enforcement and private-sector partners disrupted Sality's P2P infrastructure through sinkholing, preventing affected bots from receiving new tasking and payloads; compromised endpoints and previously delivered payloads still require remediation.
C2 tracking
Derp observations, rolling seven-day window
Samples
047e138efd0c8dbb52cc949ad66ffc45f4a64eeecd7d35fc2fa473495785fb1a 5760bf3dfa834dd40a2d43d948d7bb617014f6fd324bd8be6701e91f9176921f 6acc0714d3cbab8c42b03d03044f0c56134ed9a651bd1f7a88d8c8f56c978f6a 8684751f02d87ad7979218ee32929bd7d1dbad5f22dd78016f4d9d9144662ece 94ef48cdfeaf9733cab63ef0b640c506856ed636da5c6760ed6727a005657b19 2226fda05842c0ace78fa021724e507b72447ab58f7d4318f21143afaaae3d3e 27df1b5ba59555c9807d06970793c2eb16ca3c156bdb9276671dfb0ab005a641 62eaa5108e25386a9c96d563dca65cc75dfae6c031a670c13c27e6c1862ad7f3 6cbb25c7c431c0c5b5f0623d19ac4cd05f9f4498783ebaf201e6324bf11c2e6f 96b144bf75992b463cf212df82b9304760473047427cac343d95a51e6c6e44bf Reported operators
Sality's operations were primarily financially motivated, but three notable DDoS campaigns reveal the operator was willing to weaponize the botnet for personal or political purposes on short notice.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.