Mydoom, also known as Novarg, is a mass-mailing Windows worm first observed on 26 January 2004. It became one of the fastest-spreading e-mail worms of its era, infecting hundreds of thousands of systems globally and generating extremely large volumes of malicious mail traffic. It primarily targeted Microsoft Windows systems, especially contemporary desktop versions such as Windows 2000 and Windows XP.
Mydoom spread mainly through socially engineered e-mail messages that masqueraded as delivery failures, technical notices, or other plausible communications and carried executable attachments disguised as harmless files. It also harvested e-mail addresses from infected systems to continue propagation and attempted secondary spread through the KaZaA peer-to-peer file-sharing network. The worm used spoofed sender information, which amplified collateral e-mail disruption beyond directly infected hosts.
Once executed, Mydoom turned infected machines into remotely usable assets for malicious operators. Mydoom.A installed a backdoor that enabled remote control of compromised systems, while both major variants generated large amounts of outbound e-mail and could be used to hijack victim bandwidth and computing resources. The malware also included denial-of-service functionality: Mydoom.A was programmed to attack SCO Group, and Mydoom.B targeted Microsoft. Mydoom.B additionally altered local name-resolution behavior to block access to Microsoft and numerous security and antivirus sites, hindering remediation.
Mydoom has been associated with criminal botnet activity and was widely assessed as useful for spam operations and broader abuse of compromised hosts. Reporting has also linked at least one variant to the handle Diabl0 in the broader Mytob/Zotob malware ecosystem, though authorship of the family overall has remained unresolved. The worm’s impact was measured in major operational disruption, degraded e-mail service, and substantial economic losses across enterprises and internet infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This attack utilized the Mydoom and Dozer malware to launch a large-scale, but quite unsophisticated, DDoS attack against US and South Korean websites.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The virus did not rely on technical tricks to spread so far and wide, instead it played on the gullibility of users to open the e-mail message bearing it and click on the infected attachment.
Mydoom is effective because it arrives posing as a harmless text file containing an e-mail message... The message urges recipients to open the attached file, which is really an executable file... | It often claims to be from a colleague or friend and offers the believable explanation that the original message had to be translated into a plain-text file for delivery.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in passing as one of the notable early worms.
The ILOVEYOU virus walked so that MyDoom could run.
Malware 2004 ... Sasser Mydoom
MyDoom is referenced as a malware family for which ClamAV had a hardcoded/heuristic detection that was disabled due to false positives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.