The WANK worm was a politically motivated worm active in 1989 that targeted DEC VAX/VMS systems and propagated over DECnet rather than TCP/IP. It is described as affecting DEC VMS systems only and as being very similar to the earlier HI.COM / Father Christmas worm. CERT reported on October 16, 1989 that it was attacking SPAN network VAX/VMS systems, and noted that any DECnet-based network could be at risk because copies of the worm had been circulated.
The worm exploited weak password practices and default or poorly managed credentials on VMS systems. It spread laterally by selecting DECnet node numbers at random and attempting remote logins using blank passwords, passwords identical to usernames, usernames recovered from RIGHTSLIST, and a built-in list of standard accounts. It used PHONE to enumerate active users on remote systems and also rang them. On infected systems it modified .com files by appending code, meaning simply killing the running worm was insufficient because execution of altered command procedures could reopen the security hole.
Observed behavior included changing its process name to "NETW_" followed by a random number; CERT noted that a quick infection check was to look for a process whose name began with "NETW_". The worm changed the default DECNET account password to a random string of at least 12 characters and mailed successful compromise information, including the password used to access the system, to user GEMPAK on SPAN node 6.59. It also created a persistent backdoor condition involving the FIELD account by attempting to set that account to a known password with login permitted from any source and all privileges.
If it obtained elevated privileges, the worm could alter system behavior further. With SYSNAM privilege it set the system announcement message to the banner "WORMS AGAINST NUCLEAR KILLERS". With SYSPRV privilege it disabled mail to the SYSTEM account and modified the system login command procedure to appear to delete users' files. It also sought accounts with access to SYSUAF.DAT and, if it found a privileged account, copied itself there and started.
High-confidence indicators and artifacts mentioned in the content include the politically themed banner "WORMS AGAINST NUCLEAR KILLERS", process names beginning with "NETW_", modified .com files with appended worm code, unauthorized changes to DECNET and FIELD account credentials, and outbound notification to GEMPAK on SPAN node 6.59. The malware is associated with DECnet-connected VMS environments, including the SPAN network.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The worm takes advantage of poor password management... It looks for passwords which are the same as that of the account or are blank.
Once it hit on a legitimate node, it would attempt to run a copy of itself, either by gaining access to the target system through the default username and password “DECNET” and “DECNET”... Recall how Father Christmas searched for accounts with the username “DECNET” and password “DECNET”. WANK worm did the same, but added a few more common strings, like “SYSTEM” and “FIELD”.
The worm takes advantage of poor password management... It looks for passwords which are the same as that of the account or are blank.
Once it hit on a legitimate node, it would attempt to run a copy of itself, either by gaining access to the target system through the default username and password “DECNET” and “DECNET”... Recall how Father Christmas searched for accounts with the username “DECNET” and password “DECNET”. WANK worm did the same, but added a few more common strings, like “SYSTEM” and “FIELD”.
The worm takes advantage of poor password management, modifies .com files, creates a new account... The program then changes the default DECNET account password to a random string... tries to modify the FIELD account to a known password with login form any source and all privs.
The worm takes advantage of poor password management... It looks for passwords which are the same as that of the account or are blank.
Once it hit on a legitimate node, it would attempt to run a copy of itself, either by gaining access to the target system through the default username and password “DECNET” and “DECNET”... Recall how Father Christmas searched for accounts with the username “DECNET” and password “DECNET”. WANK worm did the same, but added a few more common strings, like “SYSTEM” and “FIELD”.
The worm takes advantage of poor password management, modifies .com files, creates a new account... The program then changes the default DECNET account password to a random string... tries to modify the FIELD account to a known password with login form any source and all privs.
It looks for a process with the first 5 characters of "NETW_". If such is found, it deletes itself (the file) and stops its process.
The worm takes advantage of poor password management... It looks for passwords which are the same as that of the account or are blank.
Once it hit on a legitimate node, it would attempt to run a copy of itself, either by gaining access to the target system through the default username and password “DECNET” and “DECNET”... Recall how Father Christmas searched for accounts with the username “DECNET” and password “DECNET”. WANK worm did the same, but added a few more common strings, like “SYSTEM” and “FIELD”.
This worm affects only DEC VMS systems and is propagated via DECnet protocols... It proceeds to attempt to access other systems by picking node numbers at random.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named 1980s-era worm (listed as part of a historical timeline). No behavior details provided in the content.
Computer worm (only referenced by name in the 1980s malware timeline; no additional details provided).
Malware ... WANK Worm
Malware ... WANK Worm ...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.