ARCV, short for Association of Really Cruel Viruses, was a virus-writing group active in the early 1990s and associated with the creation of numerous DOS malware strains, including the ARCV family and Abraxas. The group is linked to polymorphic and encrypted DOS file-infector viruses targeting COM and EXE executables. Reported ARCV-associated malware commonly appended to or overwrote executable files, spread rapidly across DOS systems, and often displayed taunting or greeting messages on trigger dates rather than causing overt destructive effects. ARCV malware was reportedly produced using virus-construction tools including PS-MPC and also associated with TPE-based development. Named authors or sub-attributions connected to ARCV malware include Apache Warrior and ICE-9. The group was reportedly prolific, producing a large number of new viruses within a short period, and was the subject of law-enforcement raids by New Scotland Yard in late 1992 and early 1993. ARCV is best characterized as an early malware authoring collective focused on virus creation and propagation rather than financially motivated intrusion or modern espionage operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A virus-writing group associated with the ARCV-n family of DOS COM and EXE infecting polymorphic viruses active in 1992.
A named virus-writing group associated with creating Abraxas and other DOS viruses, including malware produced with the PS-MPC virus creation tool and TPE-related variants.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.