Melissa was a late-1990s mass-mailing macro malware outbreak that combined Microsoft Word macro infection with self-propagation through Microsoft Outlook, making it one of the earliest Internet-scale email worms to cause major enterprise disruption. It targeted Windows systems running Microsoft Word and used malicious document macros to infect Word documents, reduce macro security settings, and automatically send itself to the first 50 contacts in a victim’s Outlook address book. Its propagation relied on social engineering, with infected email messages and attached Word documents crafted to entice recipients into opening them.
Melissa is widely associated with David L. Smith, who admitted creating and disseminating the malware in 1999. The malware was designed to evade antivirus detection and spread rapidly across corporate and government environments in North America and beyond. Although it was not primarily destructive in the sense of wiping data or directly stealing information, its mass-mailing behavior overloaded mail infrastructure, jammed business and government networks, and forced some organizations to shut down email services temporarily. Reported damages exceeded $80 million.
Melissa is best characterized as an email-borne macro worm with mass-mailing behavior. It became a landmark case in cybercrime enforcement and a pivotal early example of how commodity office software and email clients could be chained together for rapid self-propagation at Internet scale.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
When the document attachment was launched, a program was created which replicated the e-mail and sent it to the first 50 addresses in the Global Address Book of users running Microsoft's Outlook personal organiser.
The Melissa virus... started by taking over victims’ Microsoft Word program. It then used a macro to hijack their Microsoft Outlook email system and send messages to the first 50 addresses in their mailing lists.
He said that he constructed the virus to evade anti-virus software and to infect computers using the Windows 95, Windows 98 and Windows NT operating systems and the Microsoft Word 97 and Word 2000 word processing programs.
The worm targeted Microsoft Word users, and spread by sending an infected e-mail to the first 50 addresses in each victim's Microsoft Outlook address book.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of the early large-scale worms that shaped early cybersecurity history.
A major worm cited among early disruptive internet worms.
A fast-spreading macro-based email malware that infected Microsoft Word documents and abused Microsoft Outlook to mass-mail itself to contacts using social engineering lures in malicious attachments, causing widespread email server disruption.
The content includes a 'Malware' list under 'Hacking in the 1990s' that names: 'CIH, Happy99, Hare, KAK, Melissa, Michelangelo, Staog'.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.