SALTY SPIDER is the developer behind the Sality botnet, known for stealing cryptocurrency since 2018.
Analyst brief
SALTY SPIDER is a threat actor observed since January 2018, known as the developer and operator behind the long-running Sality botnet. This actor specifically targets cryptocurrency users by distributing malware designed to steal their digital assets. Their primary TTP involves leveraging the existing Sality botnet infrastructure to propagate custom cryptocurrency-stealing malware. Defenders should focus on monitoring network traffic associated with the botnet, suspicious download activities, and information-stealing attempts aimed at cryptocurrency wallets.
SALTY SPIDER
unknown
Beginning in January 2018 and persisting through the first half of the year, CrowdStrike Intelligence observed SALTY SPIDER, developer and operator of the long-running Sality botnet, distribute malware designed to target cryptocurrency users.