Happy99, also known as Ska and I-Worm, is a Microsoft Windows email and Usenet worm first seen in mid-January 1999 and described in the provided content as an early modern Internet worm. It spreads as an email attachment named HAPPY99.EXE, a 10,000-byte Win32 PE file. When executed, it displays a fireworks animation and a "Happy New Year" message as a decoy while installing itself into the Windows system directory as SKA.EXE and dropping SKA.DLL. It copies WSOCK32.DLL to WSOCK32.SKA and patches WSOCK32.DLL so it can intercept outbound network activity. The worm monitors SMTP port 25 and NNTP port 119 traffic and, when triggered, uses exported routines in SKA.DLL to append a UUencoded HAPPY99.EXE dropper to outgoing email and newsgroup messages. Infected messages may include the header "X-Spanska: Yes," and recipient addresses are logged in LISTE.SKA in the Windows system directory. The content states it infects Windows 95 and Windows 98 successfully; one source notes Windows NT targeting, while another states propagation fails on Windows NT because of bugs. Persistence can be achieved via a RunOnce registry entry at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce if WSOCK32.DLL is locked. The malware is described as causing little or no damage beyond self-propagation, but it was widely reported globally in 1999 and associated in the content with the virus writer "Spanska." Noted artifacts and cleanup-related indicators include HAPPY99.EXE, SKA.EXE, SKA.DLL, LISTE.SKA, WSOCK32.SKA, and a patched WSOCK32.DLL.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content includes a 'Malware' list under 'Hacking in the 1990s' that names: 'CIH, Happy99, Hare, KAK, Melissa, Michelangelo, Staog'.
Timeline ... Malware ... CIH ... Happy99 ... Hare ... KAK ... Melissa ... Michelangelo ... Staog
The content includes a 1990s timeline section listing malware, including: "Malware CIH Happy99 Hare KAK Melissa Michelangelo Staog".
Malware ... Happy99
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.