ILOVEYOU, also known as Love Bug and Loveletter, was a mass-mailing Windows worm that emerged on 4 May 2000 and became one of the most widespread malware outbreaks in history. It propagated through email messages carrying a purported love-letter attachment; when a recipient opened the attachment, the malware executed and resent itself to contacts, enabling extremely rapid global spread. Within hours it infected millions of systems and overwhelmed corporate and public email infrastructure, forcing many organizations to disconnect or restrict services to contain the outbreak.
ILOVEYOU primarily targeted Microsoft Windows systems and is widely remembered as one of the defining early internet-era worms. Its behavior combined social-engineering-based delivery with self-replication through users’ address books and messaging workflows, making it highly effective in enterprise environments that relied heavily on email clients. Contemporary reporting and later historical accounts consistently characterize it as wormable and capable of spreading automatically after user execution.
The malware has been associated with Onel de Guzman of the Philippines, and reporting has stated that its original motive was password theft to obtain internet access. ILOVEYOU became a landmark event in cybersecurity history because of its scale, speed, and operational disruption, and it is frequently cited alongside Code Red, Nimda, Slammer, and similar outbreaks as a catalyst for major improvements in secure software development and enterprise security practices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A mass-mailing worm referenced as historical context for the security crises that influenced Microsoft's Trustworthy Computing initiative.
A self-spreading email worm that propagated via a malicious 'love letter' attachment, infected tens of millions of Windows systems, overwhelmed email infrastructure, and was created to steal passwords for internet access.
Referenced as one of the early large-scale worms discussed for historical comparison.
A major worm cited as part of the early 2000s 'great worms' that caused significant disruption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.