Christmas Tree EXEC, also referred to as CHRISTMA EXEC, is described as the first widely disruptive computer worm. It was initially released in December 1987 and caused major disruption across the EARN, BITNET, and IBM VNET networks, with the content stating it paralyzed several international computer networks. The worm ran on IBM VM/CMS systems on IBM System/370 mainframes and was written in the REXX scripting language by an unknown student at Clausthal University of Technology. Its visible payload displayed a crude ASCII-art Christmas tree and a holiday greeting message. It propagated by reading the user’s CMS NAMES contact file and using the SENDFILE program to send itself to every address in that file. The content notes that users often executed it out of curiosity because it appeared to be a harmless Christmas card; some variants included comments to reinforce that impression, and some hid executable code in overly long lines not immediately visible on screen. The file name was actually CHRISTMA due to IBM VM filename length conventions, with EXEC as the customary file type for REXX programs. The worm is specifically associated with disruption of academic and corporate mainframe messaging/file-transfer environments rather than modern PC systems. The content also notes that its propagation concept was later compared to the 2000 ILOVEYOU worm. One cited account states it crashed 350,000 IBM terminals worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Early self-propagating email worm that displayed an ASCII Christmas tree and then emailed itself to contacts, causing widespread disruption and terminal/network crashes.
Named 1980s-era malware (listed as part of a historical timeline). No behavior details provided in the content.
Early worm (only referenced by name in the 1980s malware timeline; no additional details provided).
Hacking in the 1980s ... Malware ... Cascade ... Christmas Tree EXEC ... CyberAIDS
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.