Sality malware family
Sality is a malware family tracked by MalwareAnalyzer by Cyble across 6 publicly analyzed samples. First seen 2026-07-27, most recently 2026-08-13. Observed ATT&CK techniques include T1112, T1056.001, T1543.003.
Corpus statistics
- Publicly analyzed samples: 6
- First seen: 2026-07-27
- Last seen: 2026-08-13
- Verdicts: malicious 6
- File types: pe 6
ATT&CK techniques used by Sality
Recent Sality samples
- virussign.com_0e4e685f854146ff686027b609185cf0.vir - malicious (2026-08-13)
- virussign.com_cd071c4e8e48171b1b42e95a7eadec40.vir - malicious (2026-08-12)
- 1c8c488e0ab1941ad849da14bf9470efdd0391ff20fca23c805621fd85c61a26 - malicious (2026-08-10)
- virussign.com_4e9370874594d94ef04fedfa11865db0.vir - malicious (2026-08-01)
- virussign.com_39415367ed216b84c10eb5cbfe8163b0.vir - malicious (2026-07-28)
- virussign.com_1d983258d4585c547b36571e4be75d50.vir - malicious (2026-07-27)
Frequently asked about Sality
- What is Sality?
- Sality is a malware family tracked by MalwareAnalyzer by Cyble across 6 publicly analyzed samples. First seen 2026-07-27, most recently 2026-08-13. Observed ATT&CK techniques include T1112, T1056.001, T1543.003.
- How many Sality samples have been analyzed?
- MalwareAnalyzer by Cyble holds 6 publicly analyzed samples attributed to Sality, first seen 2026-07-27 and most recently 2026-08-13. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Sality use?
- Across our Sality samples the most frequently observed techniques are T1112 (2), T1056.001 (1), T1543.003 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Sality use?
- Sality samples in this corpus are distributed as pe (6).
- Is Sality malicious?
- 6 of 6 analyzed Sality samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends