Samy, also known as JS.Spacehero, was a self-propagating cross-site scripting worm created by Samy Kamkar and released against MySpace in October 2005. It executed in the context of authenticated MySpace browser sessions, modified victims’ profiles to display a promotional message, sent a friend request to Kamkar from each affected account, and inserted a replicating copy of itself into the victim’s profile. The worm spread when other users viewed an infected profile, reaching more than one million users within approximately 20 hours. Its propagation relied on XSS and abuse of authenticated browser actions, demonstrating the confused-deputy risks posed by client-side script execution in a trusted web origin. MySpace remediated the underlying vulnerability after the outbreak.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware 2005 PGPCoder Samy Sony rootkit
2005 PGPCoder Samy
A cross-site scripting worm that propagated on MySpace by adding the phrase "but most of all, samy is my hero" to victim profiles and sending Samy a friend request, then replicating itself when other users viewed infected profiles.
Malware 2005 ... Samy
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.