Sobig is a mass-mailing Windows worm that emerged in multiple variants from early 2003, with Sobig.F becoming one of the most widespread and fastest-spreading e-mail worms of its era. It infected millions of Microsoft Windows systems and caused major global disruption, including substantial e-mail congestion and secondary operational impacts on organizations and infrastructure-dependent networks.
Sobig propagated primarily through malicious e-mail attachments presented as benign or routine messages. When a recipient executed the attachment, the worm installed and used its own SMTP engine to send copies of itself to addresses harvested from local files on the compromised host. This made it highly effective at self-distribution without relying on the victim’s normal mail client. Sobig also used social-engineering lures in message subjects and body text to increase the likelihood of execution.
The malware exhibited both worm and Trojan characteristics: it self-replicated aggressively while also masquerading as legitimate content to induce user execution. Earlier Sobig variants reportedly installed proxy functionality using legitimate software in a backdoor-like configuration that could facilitate spam operations. Sobig.F also contained update or secondary-payload retrieval logic, being programmed to contact a set of remote systems over UDP to download or install an additional program, although the intended follow-on payload remains unclear.
Sobig was built for Microsoft Windows and is commonly associated with the major worm outbreaks that defined early-2000s Internet malware. Its most notable variant, Sobig.F, deactivated itself on a preset date. Microsoft later offered a reward for information leading to the author’s arrest. Public attribution to a specific author has been reported but remains unconfirmed, so no creator attribution can be stated with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in passing as one of the notable early worms.
A major worm outbreak that caused severe disruption and was estimated in the content to have caused perhaps $37 billion in damage.
Malware 2003 ... Welchia Sobig
2003 ... Welchia Sobig
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.