DEV Community

jordanricky1604-ship-it
jordanricky1604-ship-it

Posted on • Originally published at jordanricky1604-ship-it.github.io

Malware Deep Dive: Sality

Deep Dive: Sality (File_Infector)

Today we are analyzing the Sality malware family, which falls under the File_Infector category.

Overview

Sality is a long-running family of file-infecting Windows viruses. As documented by Malpedia (Fraunhofer FKIE), which cites F-Secure, the family has circulated in the wild since as early as 2003 and has been continually developed over the years with added capabilities such as rootkit and backdoor functionality, keeping it an active threat despite its age. It typically infects executable files on local, shared, and removable drives. Modern Sality variants can communicate over a peer-to-peer (P2P) network, allowing an operator to control a botnet of infected machines whose combined resources may be used for further malicious activity, such as attacking routers. The family is associated with the threat actor tracked as Salty Spider.

Known Aliases

Security vendors and researchers may refer to this family by several different names, including:

  • win32.sality
  • sality.ae
  • sality.gen
  • kuku
  • sality_p2p

MITRE ATT&CK Techniques

This family has been observed utilizing the following techniques:

Frequently Asked Questions

What is Sality?
Sality is a family of file-infecting Windows viruses. According to Malpedia, citing F-Secure, it has circulated since as early as 2003 and infects executable files, and modern variants form a peer-to-peer botnet of infected machines.

How does Sality spread?
Malpedia notes that Sality viruses typically infect executable files on local, shared, and removable drives. By attaching its code to legitimate executables, the virus spreads as those infected files are copied or run on other systems.

What is the Sality peer-to-peer botnet?
Per Malpedia, modern Sality variants can communicate over a peer-to-peer (P2P) network, which lets an attacker control a botnet of Sality-infected machines. The combined resources of that botnet may be used for further malicious actions, such as attacking routers.

Why has Sality remained a threat for so long?
Malpedia, citing F-Secure, explains that Sality has been developed and improved over the years with new features such as rootkit and backdoor functionality. This continued development has kept the family active and relevant despite the relative age of the malware.

What other names is Sality known by?
Sality is detected under names including Win32/Sality and variant labels such as Sality.AE and Sality.gen, and is also historically associated with the name Kuku. Malpedia tracks the family under the symbol win.sality and associates it with the threat actor Salty Spider.


This article is part of the Malware Families Catalog. Visit the original page for more details and interactive data! You can also find the full dataset on Hugging Face and Kaggle.

Top comments (0)