Saddam is an Amiga virus. The provided content identifies it as attaching itself to Disk Validator to spread on early AmigaDOS systems, where Disk Validator could be run automatically from inserted diskettes. This made removable media a key infection vector. The content specifically notes that AmigaDOS version 2.0 removed this Disk Validator infection path. It is referenced as one of the feared Amiga viruses in historical Virus-L/comp.virus FAQ material. No additional high-confidence details on payload, destructive behavior, threat actor attribution, specific targets beyond the Amiga platform, or indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Amiga virus that spreads by attaching itself to Disk Validator in early AmigaDOS versions.
Amiga virus that attaches itself to Disk Validator to propagate on early AmigaDOS systems.
In contrast to the feared Amiga viruses like the infamous Lamer Exterminator and SADDAM, Byte Bandit was not destructive.
Amiga virus that propagates by attaching itself to Disk Validator on early AmigaDOS systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.