The Morris Worm was a self-propagating Internet worm released by Robert Tappan Morris on 2 November 1988. It targeted UNIX systems connected to the early Internet, including university, government, military, and research installations. The worm gained access through a vulnerability in Sendmail, a stack buffer overflow in the finger daemon, trusted-host relationships used by rsh and rexec, and password guessing. Morris launched it from an MIT system in an effort to conceal its Cornell origin.
Its replication logic reinfected already compromised hosts far more frequently than intended, rapidly exhausting processing resources and causing many systems to crash or become unusable. The outbreak disrupted several thousand computers nationwide. Morris was convicted under the U.S. Computer Fraud and Abuse Act; the Second Circuit affirmed the conviction in 1991. The incident became a foundational event in Internet security, demonstrating the systemic impact of autonomous network-propagating malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A UNIX network worm whose reinfection behavior caused process growth and system overload. It demonstrated the capacity for automatic, user-independent propagation across networks.
An early internet worm whose replication flaw caused it to spread uncontrollably, crashing an estimated 6,000 systems.
Historic self-propagating worm cited as an early demonstration of how quickly autonomous malware can spread.
An early internet worm referenced as historical CFAA context; it spread and disrupted portions of the internet.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.