Brain, also known as Pakistani Brain, is an early DOS boot-sector virus created in 1986 and widely regarded as the first virus for IBM PC-compatible systems. It is attributed to Lahore, Pakistan-based brothers Basit and Amjad Farooq Alvi, whose company name gave the malware its name. Brain propagated through infected 360 KB floppy disks: after a system booted from an infected disk, it replaced the disk boot sector with viral code and copied itself to additional diskettes. The original boot sector was relocated to another disk area marked as bad. Brain used an early stealth technique, intercepting physical disk reads and returning the preserved original boot sector rather than the infected one, concealing its infection from users and basic inspection tools. It displayed a message containing creator contact information on infected systems. Brain is historically associated with the spread of copied software on floppy media and helped drive early awareness of PC malware and the development of antivirus tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A 1986 IBM PC/MS-DOS boot-sector virus created by Amjad and Basit Farooq, initially intended as anti-piracy protection but which spread beyond its intended scope.
Named 1980s-era malware (listed as part of a historical timeline). No behavior details provided in the content.
Early PC boot-sector virus (listed as part of 1980s malware timeline; no behavioral details provided in the content).
A computer virus notable for having identifiable creators who embedded their name and telephone number in the code; it reportedly spread through Eastern universities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.