CIH, also known as Chernobyl and Spacefiller, is a highly destructive Microsoft Windows 9x-era file-infecting virus first seen in 1998. It targets Portable Executable files on Windows 95, 98, and ME, using a space-filling infection technique that inserts its code into unused gaps within PE files so infected files typically do not increase in size, improving stealth against file-size-based detection common at the time. The malware also used ring 3 to ring 0 escalation techniques to gain kernel-level access, hook file system activity, and infect executables opened by the user.
Its payload is notable for combining disk destruction with attempted firmware sabotage. On trigger dates associated with major variants, CIH overwrites the first megabyte of the system drive, damaging the master boot record, partition information, and other critical boot structures, which renders data inaccessible and systems unbootable. On some hardware, it also attempts to corrupt writable flash BIOS contents by writing invalid data, potentially bricking the machine until the BIOS chip is reprogrammed or replaced. BIOS damage was hardware-dependent and primarily affected systems with inadequately protected flash memory.
CIH spread widely through infected software distribution, especially pirated software, but it also appeared in legitimate distribution channels, including preinstalled software on some consumer PCs and infected vendor software updates. It is attributed to Taiwanese author Chen Ing-hau and became one of the most infamous malware outbreaks of the late 1990s, with global impact concentrated on Windows 9x systems and especially severe effects in Asia. The incident is widely remembered both for its destructive payload and for demonstrating that malware could directly damage firmware as well as data storage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
CIH spread globally through pirated software channels in the summer of 1998, but several infections came from legit commercial sources like IBM’s Aptiva PCs, a batch of which shipped with CIH pre-installed in March 1999... Yamaha also distributed an infected firmware update for its CD-R400 drives, and copies of the tool Back Orifice 2000 handed out at DEF CON 7 in July of the same year also carried the virus.
Chernobyl was also known as a space filler virus for the way it concealed itself inside executables. Instead of appending code to the end of a file and inflating its size, CIH scanned Windows Portable Executable files for unused gaps between code sections and split its payload across those spaces.
Chernobyl was also known as a space filler virus for the way it concealed itself inside executables. Instead of appending code to the end of a file and inflating its size, CIH scanned Windows Portable Executable files for unused gaps between code sections and split its payload across those spaces.
When CIH activated, its dual payload first overwrote the initial megabyte of the boot drive with zeros, destroying the partition table and rendering the disk's contents inaccessible.
The CIH virus attempts to ERASE the writable FLASH BIOS of infected PC's
Destructive TTPs such as wiping or even bricking are not novel... CIH virus... overwriting a hard drive's partition table... BrickerBot destroyed more than 10 million IoT devices by writing random data to various block devices... AcidRain's wiper functionality consists of recursive file deletion combined with either overwriting raw block devices or erasing them through dedicated IOCTLs.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A compact Windows 9x file-infecting virus that concealed itself inside unused gaps of Portable Executable files, escalated from ring 3 to ring 0 to hook file system calls, infected executables users opened, and on its trigger date overwrote the initial megabyte of the boot drive and attempted to corrupt motherboard BIOS flash memory.
A destructive virus that attempts to erase the writable flash BIOS of infected PCs and overwrite the first 2,048 sectors of non-removable writable disk drives, causing systems to become unbootable and damaging disk structures.
A destructive virus that overwrote partition tables and attempted to corrupt BIOS firmware, effectively bricking infected systems.
The content includes a 'Malware' list under 'Hacking in the 1990s' that names: 'CIH, Happy99, Hare, KAK, Melissa, Michelangelo, Staog'.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.