<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>SALTY SPIDER - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/actors/salty-spider/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 02 Sep 2026 11:59:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/actors/salty-spider/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Disruption of the Sality Peer-to-Peer Botnet</title><link>https://feed.craftedsignal.io/briefs/2026-09-sality-disruption/</link><pubDate>Wed, 02 Sep 2026 11:59:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-sality-disruption/</guid><description>CrowdStrike and international law enforcement neutralized the long-running Sality P2P botnet, which leveraged polymorphic file infection and decentralized C2 to distribute malicious payloads to over 15,000 infected machines.</description><content:encoded><![CDATA[<p>On August 31, 2026, CrowdStrike's Counter Adversary Operations team, in coordination with the FBI, DOJ, DCIS, and international law enforcement agencies, executed a successful sinkholing operation against the Sality P2P botnet. Active since 2003, Sality functioned as a highly resilient, polymorphic file-infecting malware that operated without centralized command-and-control infrastructure. By leveraging a decentralized peer-to-peer architecture, infected hosts communicated directly with one another to receive tasking and updates. The botnet utilized two distinct, incompatible protocol versions (v3 and v4) that shared a common codebase but used unique cryptographic keys. The operation successfully isolated infected machines by subverting the P2P communication channel, rendering the botnet infrastructure inert and cutting off access for approximately 15,000 active nodes globally.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial infection typically occurs via polymorphic file infection of local executable files or propagation through unprotected network shares.</li>
<li>Malware establishes persistence on the host, often injecting code into legitimate processes to evade detection.</li>
<li>The infected host performs a peer discovery process to identify other active Sality nodes in the P2P network.</li>
<li>The host attempts to reach out to pre-configured URL packs to download malicious updates, configuration changes, or secondary payloads.</li>
<li>The botnet client verifies payload signatures using hardcoded RSA public keys embedded within the malware binary.</li>
<li>The malware executes functional modules (e.g., clipjacking for credential or cryptocurrency theft, proxying, or DDoS tasking).</li>
<li>The compromised host continues to spread the infection to other systems via network shares or removable media until isolated by security controls.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Sality operated for over two decades, infecting thousands of systems worldwide and maintaining a robust infrastructure capable of delivering various malicious payloads. The botnet's capabilities included credential theft, cryptocurrency transaction hijacking, and DDoS participation. The disruption rendered these capabilities inert for 15,000 active infections at the time of the operation.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Deploy the YARA rules provided in this brief to scan memory on enterprise endpoints for active Sality v3 and v4 infections.</li>
<li>Block outbound traffic to the known malicious URL packs associated with Sality v3 and v4 at the network perimeter.</li>
<li>Scan internal network shares for infected executables that may attempt to re-propagate the Sality file-infector.</li>
<li>Review endpoint logs for unexpected execution of processes that attempt to verify signatures using the known RSA public keys embedded in Sality binaries.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>botnet</category><category>p2p</category><category>malware</category><category>file-infection</category><category>counter-adversary-operations</category></item></channel></rss>