Blaster, also known as Lovsan, is a self-propagating Windows network worm that emerged in 2003 and rapidly infected unpatched Microsoft systems by exploiting a vulnerability in the RPC DCOM service. It spread without user interaction by scanning random IP addresses for vulnerable hosts and launching remote compromise attempts, making it a prominent example of the early-2000s Windows worm outbreaks alongside Code Red, SQL Slammer, Nimda, and Sasser. Reported impact included widespread operational disruption across enterprise and critical-infrastructure environments, including infections observed in systems associated with the 2003 U.S. Northeast blackout and outages in industrial production environments.
Blaster primarily targeted Windows 2000 and Windows XP systems. Contemporary reporting also noted that although the vulnerable code existed in Windows Server 2003, that platform was not successfully infected by the worm because compiler-based protections caused the affected service to terminate before infection could complete. Multiple variants appeared in the wild. One notable variant was linked to Jeffrey Lee Parson, who admitted modifying the original worm and adding a Trojan-style backdoor capability to infected machines.
Blaster is best characterized as a worm because its defining behavior was autonomous network propagation through vulnerability exploitation and large-scale scanning. Its activity generated significant network noise and disruption, and it became one of the most consequential common worms affecting organizations in the 2002-2006 period. Blaster is also frequently cited in analyses of SCADA and critical-infrastructure risk because infections reached operational technology-adjacent environments through weak segmentation, unpatched hosts, and infected portable systems connected during maintenance or troubleshooting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A US teenager has been arrested under suspicion of creating the Blaster or LoveSan.B virus, and court papers reveal intriguing details about the origin of the Blaster worm. Jeffrey Lee Parson, 18, has admitted modifying the original Blaster worm using a text editor, adding a Trojan to allow backdoor access to infected computers and releasing it into the wild.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Jeffrey Lee Parson, 18, has admitted modifying the original Blaster worm using a text editor, adding a Trojan to allow backdoor access to infected computers and releasing it into the wild.
The code which Blaster took advantage of was in the released version of Windows 2003 :( but the worm itself did not infect Windows Server 2003 machines, here's why: the /GS flag. The buffer-overrun was detected by the -GS handling code, which caused the OS to shut the RCPSS process down.
The code which Blaster took advantage of was in the released version of Windows 2003 :( but the worm itself did not infect Windows Server 2003 machines, here's why: the /GS flag. The buffer-overrun was detected by the -GS handling code, which caused the OS to shut the RCPSS process down.
Blaster first appeared on Monday and quickly spread to computers worldwide by exploiting a known security vulnerability in Microsoft’s Windows operating system. By Friday, the worm, which targets a Windows component for handling RPC (Remote Procedure Call) protocol traffic called the Distributed Component Object Model (DCOM) interface...
In addition to infecting vulnerable Windows machines, Blaster worm was programmed to launch a denial of service (DOS) attack against windowsupdate.com, an Internet domain owned by Microsoft and used to distribute software updates to Windows customers beginning on Saturday.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm mentioned only as historical background in the author's biography, not as part of the article's subject matter.
A worm mentioned only as part of the author's past reporting credentials, not as part of the article's subject matter.
A worm mentioned only as historical background in the author's biography.
Referenced only as a historical malware incident covered by the author.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.