{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/salty-spider/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["SALTY SPIDER"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["botnet","p2p","malware","file-infection","counter-adversary-operations"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eOn August 31, 2026, CrowdStrike's Counter Adversary Operations team, in coordination with the FBI, DOJ, DCIS, and international law enforcement agencies, executed a successful sinkholing operation against the Sality P2P botnet. Active since 2003, Sality functioned as a highly resilient, polymorphic file-infecting malware that operated without centralized command-and-control infrastructure. By leveraging a decentralized peer-to-peer architecture, infected hosts communicated directly with one another to receive tasking and updates. The botnet utilized two distinct, incompatible protocol versions (v3 and v4) that shared a common codebase but used unique cryptographic keys. The operation successfully isolated infected machines by subverting the P2P communication channel, rendering the botnet infrastructure inert and cutting off access for approximately 15,000 active nodes globally.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial infection typically occurs via polymorphic file infection of local executable files or propagation through unprotected network shares.\u003c/li\u003e\n\u003cli\u003eMalware establishes persistence on the host, often injecting code into legitimate processes to evade detection.\u003c/li\u003e\n\u003cli\u003eThe infected host performs a peer discovery process to identify other active Sality nodes in the P2P network.\u003c/li\u003e\n\u003cli\u003eThe host attempts to reach out to pre-configured URL packs to download malicious updates, configuration changes, or secondary payloads.\u003c/li\u003e\n\u003cli\u003eThe botnet client verifies payload signatures using hardcoded RSA public keys embedded within the malware binary.\u003c/li\u003e\n\u003cli\u003eThe malware executes functional modules (e.g., clipjacking for credential or cryptocurrency theft, proxying, or DDoS tasking).\u003c/li\u003e\n\u003cli\u003eThe compromised host continues to spread the infection to other systems via network shares or removable media until isolated by security controls.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSality operated for over two decades, infecting thousands of systems worldwide and maintaining a robust infrastructure capable of delivering various malicious payloads. The botnet's capabilities included credential theft, cryptocurrency transaction hijacking, and DDoS participation. The disruption rendered these capabilities inert for 15,000 active infections at the time of the operation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the YARA rules provided in this brief to scan memory on enterprise endpoints for active Sality v3 and v4 infections.\u003c/li\u003e\n\u003cli\u003eBlock outbound traffic to the known malicious URL packs associated with Sality v3 and v4 at the network perimeter.\u003c/li\u003e\n\u003cli\u003eScan internal network shares for infected executables that may attempt to re-propagate the Sality file-infector.\u003c/li\u003e\n\u003cli\u003eReview endpoint logs for unexpected execution of processes that attempt to verify signatures using the known RSA public keys embedded in Sality binaries.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-02T11:59:42Z","date_published":"2026-09-02T11:59:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sality-disruption/","summary":"CrowdStrike and international law enforcement neutralized the long-running Sality P2P botnet, which leveraged polymorphic file infection and decentralized C2 to distribute malicious payloads to over 15,000 infected machines.","title":"Disruption of the Sality Peer-to-Peer Botnet","url":"https://feed.craftedsignal.io/briefs/2026-09-sality-disruption/"}],"language":"en","title":"CraftedSignal Threat Feed - SALTY SPIDER","version":"https://jsonfeed.org/version/1.1"}