Netskope Threat Labs

Sality

ATP Sandbox Adv. HeuristicsAV

Sality is a file infecting worm that has been around since 2003 and spreads through infected executables, network shares, and removable drives. It delivers a variety of different malware payloads, steals cryptocurrency, and provides cyberattackers remote access through a peer to peer network that has kept the botnet alive for two decades. Its Russian origins and durable infrastructure make it one of the longest lived active malware families, and infections require careful remediation because every infected executable carries the malware.

First seen
January 2022
Last seen
October 2026
Alert Name
DeepScan:Generic.Sality.3.438CF649
DeepScan:Generic.Sality.3.4A2C2355
DeepScan:Generic.Sality.3.FBD1CE9D
Dropped:Win32.Sality.3
Dropped:Win32.Sality.H
Dropped:Win32.Sality.RA
Gen:Win32.Sality.Dam
Generic.Sality.3.64043B7E
Trojan.Dropper.Sality.C
Win32.Sality.2.NX