Cascade, also known as Herbstlaub, is a DOS-era memory-resident file-infecting computer virus discovered in Germany in 1988. It targets IBM PC-compatible DOS systems and propagates by infecting executable files. Once resident, it can infect additional eligible programs as they are used. Cascade was an early encrypted virus: it encrypts most of its body using a varying key to impede signature-based detection, but retains a consistent decryption routine and is therefore not polymorphic. Its well-known payload causes characters displayed on the screen to fall downward and accumulate at the bottom. Multiple variants exist, including defective mutations that may repeatedly reinfect a file. Cascade can also operate in DOS sessions hosted by some versions of Microsoft Windows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Yes, both file-infecting and boot sector viruses can infect HPFS partitions. File-infecting viruses function normally and can activate and do their dirty deeds... any DOS session that executes a program infected by a virus that makes itself memory resident would itself become infected.
The technique that malware programmers use to make the malware difficult to read and understand is known as Obfuscation. The basic purpose of this technique is to hide the malicious behavior of malware.
The main purpose of this technique is to avoid antivirus detection and static code analysis. This method also delay the process of investigation.
A POLYMORPHIC virus is one that produces varied but operational copies of itself... One method of evading scan string-driven virus detectors is self-encryption with a variable key.
Yes, both file-infecting and boot sector viruses can infect HPFS partitions. File-infecting viruses function normally and can activate and do their dirty deeds... most of the well-behaved resident viruses that infect only COM files (Cascade is an excellent example), will work perfectly in a 'DOS box'.
Yes, both file-infecting and boot sector viruses can infect HPFS partitions. File-infecting viruses function normally and can activate and do their dirty deeds... any DOS session that executes a program infected by a virus that makes itself memory resident would itself become infected.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historical virus mentioned in a list without further technical detail.
Named 1980s-era malware (listed as part of a historical timeline). No behavior details provided in the content.
Computer virus (only referenced by name in the 1980s malware timeline; no additional details provided).
Hacking in the 1980s ... Malware ... Byte Bandit ... Cascade ... Christmas Tree EXEC
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.