Klez is a mass-mailing Windows computer worm first observed in October 2001. It propagates through email by harvesting recipient addresses from infected users’ address books and sending itself to those contacts in messages with changing subjects, bodies, and attachments. It targeted vulnerable Microsoft Outlook and Outlook Express configurations by abusing an Internet Explorer Trident HTML-rendering flaw that could permit execution through crafted HTML email; other variants relied on deceptive attachments and lures posing as Microsoft patches or Klez-removal tools. Klez spoofed sender addresses using contacts from the victim’s address book, complicating identification of the actual infected sender. It could infect files, replicate through victim environments, and in some variants attach local files to outbound messages, creating a risk of unintended data disclosure. Klez.H was responsible for a major worldwide outbreak in 2002, and Klez remained prevalent in email-borne malware detections for years afterward.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A mass-mailing Windows worm that harvested address-book contacts, spoofed email senders, propagated through deceptive email messages, infected files, copied itself across victim networks, and used variable email lures and random behavior to hinder identification.
Referenced in passing as one of the notable early worms.
Malware 2001 ... Nimda Klez
2001 ... Nimda Klez
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.