Nimda is a major early-2000s Windows worm, first seen in 2001, notable for combining multiple propagation methods into a fast-spreading hybrid outbreak. Its name is derived from spelling “admin” backwards. Nimda targeted Microsoft Windows environments and spread through infected email attachments, compromised or vulnerable Microsoft IIS web servers, weak passwords on local networks, and backdoors left by prior infections such as Code Red II. It exploited a directory traversal flaw in IIS and also propagated by scanning aggressively for additional victims, generating substantial network traffic and widespread operational disruption.
Beyond self-propagation, Nimda infected executable files on compromised systems, which complicated cleanup and recovery. Its multi-vector design allowed it to move both across the internet and within internal networks, making it more disruptive than single-channel worms of the same era. Organizations reported significant impact, and high-profile victims included major technology and telecommunications companies. Nimda is widely cited alongside Code Red, ILOVEYOU, SQL Slammer, Blaster, and Sasser as one of the defining worms that drove the early-2000s internet security crisis and helped catalyze stronger defensive practices such as improved patching, default host firewalls, and blocking of executable email attachments. The author of Nimda has not been publicly identified.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This vulnerability is now being actively exploited. More information about the activity and remediation can be found in CERT Advisory CA-2001-26: Nimda Worm.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The worm also exploited weak passwords to speed across different machines on local networks.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm mentioned as one of the major early-2000s outbreaks affecting Microsoft products and prompting stronger security efforts.
Referenced as an early internet worm and as an example of attacks that spread so quickly victims had little chance to respond.
A major worm referenced as part of the disruptive early-2000s worm outbreaks.
...it’s important to remember that NIMDA happened.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.