The Morris Worm was a self-replicating Unix worm released in November 1988 by Robert Tappan Morris and is widely regarded as the first major Internet worm. It propagated automatically across interconnected university, government, military, and research systems on the early Internet, causing widespread disruption by exhausting system resources and rendering many hosts unusable. Estimates commonly place the number of affected systems at roughly 6,000, a significant share of the Internet-connected population at the time.
The worm spread by exploiting multiple weaknesses and trust relationships in networked Unix environments, including a flaw in the finger daemon, weaknesses in SENDMAIL, trusted-host mechanisms, and password guessing. Its design aimed to move broadly while avoiding easy detection, but a flawed reinfection mechanism caused it to replicate far more aggressively than intended, leading to denial of service conditions on infected machines. The malware is historically associated with early exploitation of a stack buffer overflow in the finger service.
The Morris Worm is notable less for data theft than for autonomous propagation and operational disruption. It demonstrated how insecure network services and implicit trust between systems could enable rapid compromise at Internet scale, and it became a foundational case in both incident response history and U.S. cybercrime law. Robert Tappan Morris became the first person convicted under the Computer Fraud and Abuse Act in connection with releasing the worm. The incident helped drive lasting changes in vulnerability management, network defense, and coordinated handling of major cyber incidents.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An early internet worm referenced as historical CFAA context; it spread and disrupted portions of the internet.
A self-propagating worm referenced as a historical comparison point for the significance of the AI-driven intrusion.
A self-propagating internet worm cited as a historical comparison for the significance of the OpenAI/Hugging Face incident.
Historic computer worm referenced as a comparison point for the scale of potential future security incidents.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.