The Father Christmas worm, also known as the HI.COM VMS worm, was a DECnet-propagating computer worm that targeted VAX/VMS systems and was released in December 1988. It exploited default passwords on DECnet-connected VMS nodes to gain access and spread across networks. The worm was detected on NASA’s Space Physics Analysis Network (SPAN) around 17:00 EST on December 22, 1988, and reporting at the time indicated it may have spread to more than 6,000 nodes. Its functionality was limited: it created a file named HI.COM and, at 00:30 on December 24, sent a “Father Christmas” greeting message to users listed in the local rights database of infected systems. The content states it did not perform actions beyond sending this message. The worm is reported to have originated from a computer on DECnet in Switzerland and was attributed to a person using the multi-user login name PHSOLIDE. A contemporaneous mitigation was to pre-create an empty HI.COM file so the worm could not create its own. The incident led to strengthened security measures on SPAN and the broader DECnet Internet, which later aided rapid containment of a nearly identical worm released into the Easynet intranet in January 1989.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Once it hit on a legitimate node, it would attempt to run a copy of itself, either by gaining access to the target system through the default username and password “DECNET” and “DECNET”... Recall how Father Christmas searched for accounts with the username “DECNET” and password “DECNET”. WANK worm did the same, but added a few more common strings, like “SYSTEM” and “FIELD”.
Once it hit on a legitimate node, it would attempt to run a copy of itself, either by gaining access to the target system through the default username and password “DECNET” and “DECNET”... Recall how Father Christmas searched for accounts with the username “DECNET” and password “DECNET”. WANK worm did the same, but added a few more common strings, like “SYSTEM” and “FIELD”.
Once it hit on a legitimate node, it would attempt to run a copy of itself, either by gaining access to the target system through the default username and password “DECNET” and “DECNET”... Recall how Father Christmas searched for accounts with the username “DECNET” and password “DECNET”. WANK worm did the same, but added a few more common strings, like “SYSTEM” and “FIELD”.
Once it hit on a legitimate node, it would attempt to run a copy of itself, either by gaining access to the target system through the default username and password “DECNET” and “DECNET”... Recall how Father Christmas searched for accounts with the username “DECNET” and password “DECNET”. WANK worm did the same, but added a few more common strings, like “SYSTEM” and “FIELD”.
It began by searching a network for random node numbers. Once it hit on a legitimate node... The WANK worm was, structurally, much like Father Christmas... They used the same method of finding new computers in a network–by conducting random node number searches.
Once it hit on a legitimate node, it would attempt to run a copy of itself, either by gaining access to the target system through the default username and password “DECNET” and “DECNET”, or by exploiting a legitimate built-in program that allowed a node to start a task on a remote computer.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DECnet-propagating worm targeting VAX/VMS systems that created a HI.COM file and, on Dec 24, sent a “Father Christmas” greeting message to local users; no other actions were described.
A computer worm targeting VMS systems that exploited default passwords on privileged accounts to gain access and spread via DECnet-connected nodes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.