SCA is an Amiga boot sector virus that appeared in November 1987 and is described in the content as the first computer virus created for the Amiga platform and one of the first to gain public notoriety. It spreads to write-enabled floppy disks inserted into an infected system. Its payload displays a message every 15th copy after a warm reboot, including the phrase "Something wonderful has happened Your AMIGA is alive !!!" and a notice that some disks are infected by a virus. The malware can render disks with custom bootblocks, such as games, unusable. It is also stated to checksum as an original filesystem (OFS) bootblock and can damage newer Amiga filesystems if users do not properly remove it; the content gives an example recovery command of "install df0: FFS FORCE" for a fast filesystem floppy. The name "SCA" is stated to refer to the Swiss Cracking Association, suggesting Switzerland as the geographic origin, and the virus is probably attributed to an SCA member known as "CHRIS." The content further states that the Mega-Mighty SCA later produced the first Amiga virus checker that removed SCA, reportedly in response to estimates that about 40% of Amiga users had encountered it due to piracy and floppy-disk sharing. The content also notes that SCA inspired later Amiga viruses including Byte Bandit and Byte Warrior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named 1980s-era malware (listed as part of a historical timeline). No behavior details provided in the content.
Computer virus (only referenced by name in the 1980s malware timeline; no additional details provided).
Hacking in the 1980s ... Malware ... Ping-Pong ... SCA ... Scores
Malware ... SCA
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.