Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2009 – Operation Troy This attack utilized the Mydoom and Dozer malware to launch a large-scale, but quite unsophisticated, DDoS attack against US and South Korean websites.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DDoS malware used alongside Mydoom in Operation Troy against US and South Korean websites.
Malware used alongside Mydoom in Operation Troy to launch DDoS attacks.
Malware used to conduct distributed denial-of-service attacks against government, financial, and media websites in the U.S. and South Korea.
Malware used in the July 2009 attacks against South Korean and U.S. government and financial websites. It was spread via email and included a time bomb that overwrote files and the first megabyte of the hard drive, destroying the MBR and partition table.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.