Skip to content

Sality

Sality is a long-running Windows malware family first observed in 2003.

Profile source: Mallory opens in a new tab

Sality

Family profile

Sality is a long-running Windows malware family first observed in 2003. It is a polymorphic executable-file infector that evolved into a decentralized peer-to-peer botnet and malware-delivery platform. It infects Windows executables, propagates through network shares and removable storage, and enrolls compromised hosts into a custom P2P network that distributes signed payload instructions and, in later variants, payload files directly.

Sality incorporates substantial defense-evasion and persistence functionality, including process injection, security-product termination, interference with security updates and resources, Windows security-configuration tampering, and kernel-level components in some variants. Historical variants also performed keylogging, credential theft, and data exfiltration. The botnet has delivered spam relays, proxy components, information stealers, web compromise tooling, distributed password-cracking payloads, and DDoS payloads.

A major long-term payload family delivered through Sality was EggJagger, which hijacked cryptocurrency wallet addresses copied to the clipboard to redirect payments to attacker-controlled wallets. Sality operations have primarily been assessed as financially motivated, although the botnet has also been used in DDoS campaigns with apparent politically aligned and personal-grievance motivations. CrowdStrike tracks activity associated with Sality under the SALTY SPIDER designation. International law-enforcement and private-sector partners disrupted Sality's P2P infrastructure through sinkholing, preventing affected bots from receiving new tasking and payloads; compromised endpoints and previously delivered payloads still require remediation.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
3 IP / 12 hostnames

Leading locations

  • CN4
  • US4
  • DE3
  • IT1

Leading providers

  • Leaseweb Deutschland GmbH3
  • Amazon.com, Inc.2
  • California Department of Technology1
  • CHINANET BACKBONE1
  • CHINATELECOM JiangSu YangZhou IDC network1
  • IDC, China Telecommunications Corporation1

Infrastructure traits

  • Hosting 7

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
SALTY SPIDER

Sality's operations were primarily financially motivated, but three notable DDoS campaigns reveal the operator was willing to weaponize the botnet for personal or political purposes on short notice.

Exploited software

Vulnerabilities linked to Sality

2 CVEs

MITRE ATT&CK

Sality in ATT&CK

43 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.