Salgorea malware family
Salgorea is a malware family tracked by MalwareAnalyzer by Cyble across 85 publicly analyzed samples. First seen 2026-07-31, most recently 2026-08-18. Observed ATT&CK techniques include T1543.003, T1112, T1105.
Corpus statistics
- Publicly analyzed samples: 85
- First seen: 2026-07-31
- Last seen: 2026-08-18
- Verdicts: malicious 85
- File types: pe 85
ATT&CK techniques used by Salgorea
Recent Salgorea samples
- ED49.tmp - malicious (2026-08-18)
- virussign.com_f6790123345e0a86560a620abaeffa10.vir - malicious (2026-08-18)
- C8C9.tmp - malicious (2026-08-18)
- 3A06.tmp - malicious (2026-08-18)
- 4d90904f1fb4add37732614cdbf6be7612ba5e0acb9afb87cfe2d4d1868cbc6d - malicious (2026-08-18)
- 7ee2d74db8e47f1b8eaf4c25acdd26749f78c6b8e07cb9891cbef417285f44cd - malicious (2026-08-18)
- f1b82f146f4f61e9bba27ac65830fc5694f3c3991fa6b7a8e1b47d7ddce6abcb - malicious (2026-08-17)
- e1f6bbf8ce9dc4472bf3e675ea2662fa5e28eda579b8e72ef0eaf4a22fc55bfb - malicious (2026-08-11)
- fa1384e53fd5ba303423ccb5ea09aee03bfc16ca4487e528f3b4126c0d445cf1 - malicious (2026-08-11)
- virussign.com_d51897605d38e3ee24dcb3a46f21e700.vir - malicious (2026-08-11)
- afd40f59dcf70ebf9c97a2aedf2c08affcf58a2b7501272ceac460cca181acb1 - malicious (2026-08-10)
- virussign.com_db3145c85f6e87d2346d445c5986b710.vir - malicious (2026-08-10)
- 1959d65d48d088fc5e19fd5351c67989adc5e8690ed0816ad1c43ae5ab1e22e2 - malicious (2026-08-10)
- 6b3a4e78d397264d25d416a8c5db50b17812cff478cde10222ce3cfeb9f650c3 - malicious (2026-08-10)
- 26f7342faa7451f1c199b364237b9f4238fb77142a67a9212df800423f57af4a - malicious (2026-08-10)
- 69cdea3c78f0b0ec1ccc7d44a5ee5fc9db888c360a44cb3fd8dce7fe57651058 - malicious (2026-08-10)
- fd7236c9d7f212f40e70ffbdae54d5000502eb467b104e091305dfff7e834309 - malicious (2026-08-10)
- 13728fdcc335f161a8d433071ca3a38a588bdec817d19cb66aaf759810ae6702 - malicious (2026-08-10)
- 443445aa2dcdad4829c8438e3a1cdba4cb3e51e856d937cb86a17efcb6d3509f - malicious (2026-08-10)
- e17b34cb4982c53758bb510e9029d1293db40a0fade7d93ad079fae72c5ca5b8 - malicious (2026-08-10)
- 5a881a6d4059880b50d3131fa1de446c366743cc48c8df3e10d19bdcdbb5dcb9 - malicious (2026-08-10)
- 755ac4cca522ac5bc1c749b7209cf1dfd18c293cb3773545199c75098d02ab78 - malicious (2026-08-10)
- 0bdb6e328fe98140289dbbf520a1e3bb6a0f5a5bfbad3440fab28ca9ec06eb43 - malicious (2026-08-10)
- afedd244ddfb7af0ad8adbe82aa5eda22eb38a9ec74eaf525e69b06afdf5871d - malicious (2026-08-10)
Frequently asked about Salgorea
- What is Salgorea?
- Salgorea is a malware family tracked by MalwareAnalyzer by Cyble across 85 publicly analyzed samples. First seen 2026-07-31, most recently 2026-08-18. Observed ATT&CK techniques include T1543.003, T1112, T1105.
- How many Salgorea samples have been analyzed?
- MalwareAnalyzer by Cyble holds 85 publicly analyzed samples attributed to Salgorea, first seen 2026-07-31 and most recently 2026-08-18. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Salgorea use?
- Across our Salgorea samples the most frequently observed techniques are T1543.003 (73), T1112 (68), T1105 (65). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Salgorea use?
- Salgorea samples in this corpus are distributed as pe (85).
- Is Salgorea malicious?
- 85 of 85 analyzed Salgorea samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends