Staog is a Linux computer virus described as the first computer virus written for the Linux operating system. It was discovered on October 20, 1996. The malware targeted Linux ELF binaries and is described as a file virus with an infection length of 4,744 bytes. Staog exploited three known Linux vulnerabilities to gain root access on infected systems: a mount buffer overflow, a tip buffer overflow, and a suidperl bug. The tip flaw was especially significant because early Linux systems often installed tip as a setuid-root binary. Using these vulnerabilities, Staog could obtain root privileges, remain resident on the infected system, and infect executed binaries. The virus was written in assembly language and is attributed to the Australian hacker group VLAD; one source specifically attributes it to Quantum of VLAD and lists Australia as the origin. VLAD is also associated with the Windows 95 virus Boza. The exploited vulnerabilities were fixed soon after discovery and have since been patched in major Linux distributions. The content states Staog has not been detected in the wild since its initial outbreak.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Linux computer virus Staog was the first computer virus written for the Linux operating system. It was discovered in the autumn, October 20, of 1996... Staog manages to undermine the root access of the infected Linux system via three known kernel vulnerabilities... Then, it would infect executed binaries.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
“…mount buffer overflow, tip buffer overflow and one suidperl bug…” | “Staog manages to undermine the root access of the infected Linux system via three known kernel vulnerabilities: mount buffer overflow, tip buffer overflow and one suidperl bug…” | “For tip command, since in early versions of Linux, it was often installed as a setuid root binary… Staog took advantage of that, along with the buffer overflow in tip to gain root privilege access…”
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content includes a 'Malware' list under 'Hacking in the 1990s' that names: 'CIH, Happy99, Hare, KAK, Melissa, Michelangelo, Staog'.
Timeline ... Malware ... CIH ... Happy99 ... Hare ... KAK ... Melissa ... Michelangelo ... Staog
The content includes a 1990s timeline section listing malware, including: "Malware CIH Happy99 Hare KAK Melissa Michelangelo Staog".
... Malware ... Staog ...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.