Sality

First seen
2003-01-01 00:00:00
Malware type
virus, botnet, rootkit, backdoor
Family
Malware family
Last IoC activity
2026-07-22 03:16:14
Profile updated
2026-07-07 13:00:56

Context

F-Secure states that the Sality virus family has been circulating in the wild as early as 2003. Over the years, the malware has been developed and improved with the addition of new features, such as rootkit or backdoor functionality, and so on, keeping it an active and relevant threat despite the relative age of the malware. Modern Sality variants also have the ability to communicate over a peer-to-peer (P2P) network, allowing an attacker to control a botnet of Sality-infected machines. The combined resources of the Sality botnet may also be used by its controller(s) to perform other malicious actions, such as attacking routers. Infection Sality viruses typically infect executable files on local, shared and removable drives. In earlier variants, the Sality virus simply added its own malicious code to the end of the infected (or host) file, a technique known as prepending. The viral code that Sality inserts is polymorphic, a form of complex code that is intended to make analysis more difficult. Earlier Sality variants were regarded as technically sophisticated in that they use an Entry Point Obscuration (EPO) technique to hide their presence on the system. This technique means that the virus inserts a command somewhere in the middle of an infected file's code, so that when the system is reading the file to execute it and comes to the command, it forces the system to 'jump' to the malware's code and execute that instead. This technique was used to make discovery and disinfection of the malicious code harder. Payload Once installed on the computer system, Sality viruses usually also execute a malicious payload. The specific actions performed depend on the specific variant in question, but generally Sality viruses will attempt to terminate processes, particularly those related to security programs. The virus may also attempt to open connections to remote sites, download and run additional malicious files, and steal data from the infected machine.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Sality_Auto (yara-rule)

Related threat objects

  • Sality (infrastructure)

Reports & references

  • CISA — Aa22 110A (report)
  • CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
  • Mandiant — Pe File Infecting Malware Ot (report)
  • Palo Alto Unit 42 — C2 Traffic (report)
  • researchgate.net — Botnet Protocol Inference In The Presence Of Encrypted Traffic (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sality (report)
  • Broadcom/Symantec — Sality Peer To Peer Viral Network (report)
  • botconf.eu — Ok P18 Kleissner Sality (report)
  • dragos.com — The Trojan Horse Malware Password Cracking Ecosystem Targeting Industrial Operators (report)
  • gist.githubusercontent.com — Sality Extractor.Py (report)

External references