Blaster, also known as the MSBlast or LoveSan worm, is a Windows network worm first observed in August 2003. It propagates without user interaction by scanning random network addresses for unpatched Microsoft Windows systems vulnerable to a remote procedure call flaw, then exploiting those systems to spread. The worm’s aggressive scanning and repeated infection attempts caused substantial network disruption and contributed to outages in enterprise and industrial environments. Blaster primarily affected older Windows systems; Windows Server 2003 contained the vulnerable code but resisted successful infection because compiler stack-overrun protection terminated the affected RPC service. Multiple variants circulated. A variant attributed to Jeffrey Lee Parson added a Trojan backdoor capability to compromised hosts, but that behavior is not inherent to the original Blaster worm.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A US teenager has been arrested under suspicion of creating the Blaster or LoveSan.B virus, and court papers reveal intriguing details about the origin of the Blaster worm. Jeffrey Lee Parson, 18, has admitted modifying the original Blaster worm using a text editor, adding a Trojan to allow backdoor access to infected computers and releasing it into the wild.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Jeffrey Lee Parson, 18, has admitted modifying the original Blaster worm using a text editor, adding a Trojan to allow backdoor access to infected computers and releasing it into the wild.
The code which Blaster took advantage of was in the released version of Windows 2003 :( but the worm itself did not infect Windows Server 2003 machines, here's why: the /GS flag. The buffer-overrun was detected by the -GS handling code, which caused the OS to shut the RCPSS process down.
The code which Blaster took advantage of was in the released version of Windows 2003 :( but the worm itself did not infect Windows Server 2003 machines, here's why: the /GS flag. The buffer-overrun was detected by the -GS handling code, which caused the OS to shut the RCPSS process down.
Blaster first appeared on Monday and quickly spread to computers worldwide by exploiting a known security vulnerability in Microsoft’s Windows operating system. By Friday, the worm, which targets a Windows component for handling RPC (Remote Procedure Call) protocol traffic called the Distributed Component Object Model (DCOM) interface...
In addition to infecting vulnerable Windows machines, Blaster worm was programmed to launch a denial of service (DOS) attack against windowsupdate.com, an Internet domain owned by Microsoft and used to distribute software updates to Windows customers beginning on Saturday.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A historically cited wormable malware example associated with exploitation of RPC vulnerabilities.
A worm mentioned only as historical background in the author's biography, not as part of the article's subject matter.
A worm mentioned only as part of the author's past reporting credentials, not as part of the article's subject matter.
A worm mentioned only as historical background in the author's biography.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.