Sasser is a self-propagating Windows worm first released in 2004 that targeted vulnerable Windows 2000 and Windows XP systems by exploiting a flaw in the Local Security Authority Subsystem Service addressed by Microsoft bulletin MS04-011 (CVE-2003-0533). Unlike email-borne worms common in the same era, Sasser spread autonomously over the network without user interaction by scanning for exposed hosts, exploiting the vulnerability remotely, and transferring itself from infected systems to newly compromised machines. Multiple variants appeared rapidly after the initial release.
A hallmark of Sasser infections was instability caused by crashes in the LSASS process, often resulting in forced system shutdowns or reboots. Some variants scanned so aggressively that they generated substantial network congestion, contributing to service disruption beyond the directly infected hosts. The worm caused widespread operational impact across government agencies, transportation providers, financial institutions, postal services, hospitals, media organizations, and other enterprises in multiple countries. Reported effects included unusable workstations, degraded network links, interrupted business operations, and temporary reversion to manual processes.
Sasser is strongly associated with German malware author Sven Jaschan, who admitted to creating the worm and was later convicted in Germany. Reporting has also linked the worm’s development to publicly available exploit code circulating at the time. The outbreak became one of the defining Windows worm incidents of the early 2000s and is frequently cited alongside Code Red, Slammer, Blaster, and Nimda as an example of large-scale vulnerability-driven malware propagation. Sasser also appeared in incident analyses involving industrial and critical infrastructure environments, where common worms exploiting commodity Windows systems contributed materially to operational disruptions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in passing as one of the notable early worms.
Malware 2004 ... NetSky Sasser Mydoom
2004 ... NetSky Sasser
A Windows worm mentioned as part of the megaworm era that followed Nimda.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.