Ping-Pong, also known as Boot, Bouncing Ball, Bouncing Dot, Italian, Italian-A, and VeraCruz, is an early DOS boot-sector virus discovered at the Politecnico di Torino in Italy on March 1, 1988. Its author is unknown. It spread primarily through infected floppy diskettes and became memory resident after a system booted from infected media. The original Ping-Pong.A variant infected floppy-disk boot sectors; later variants, including Ping-Pong.B and Ping-Pong.C, also infected hard-disk boot sectors and could interfere with attempts to replace an infected boot sector. The virus stored the displaced boot sector in the disk's final cluster and marked that cluster as bad, helping prevent DOS from overwriting it. It infected accessible active drives and could infect certain non-bootable hard-disk partitions. Its principal payload activated when disk access occurred exactly on the half-hour, displaying a bouncing ball or dot in text or graphics modes. Although it generally caused no deliberate destructive effects, its use of an instruction incompatible with later x86 processors could crash some 286, V20, 386, and 486 systems during payload execution. Ping-Pong was among the most prevalent and widely recognized boot-sector viruses of its era before Stoned became more common.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
While the virus is active, one cannot replace the boot sector—it either prevents writing to it or it immediately re-infects it. | The Ping-Pong virus ... is a boot sector virus ... Computers could be contaminated by an infected diskette ... used by the virus to store the original boot sector ... Later variants of this virus such as Ping-Pong.B and Ping-Pong.C also infect the hard disk boot sector as well.
While the virus is active, one cannot replace the boot sector—it either prevents writing to it or it immediately re-infects it. | The Ping-Pong virus ... is a boot sector virus ... Computers could be contaminated by an infected diskette ... used by the virus to store the original boot sector ... Later variants of this virus such as Ping-Pong.B and Ping-Pong.C also infect the hard disk boot sector as well.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historical virus mentioned in a list without further technical detail.
Named 1980s-era malware (listed as part of a historical timeline). No behavior details provided in the content.
Boot-sector virus (only referenced by name in the 1980s malware timeline; no additional details provided).
Hacking in the 1980s ... Malware ... nVIR ... Ping-Pong ... SCA
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.