Ghostball is a DOS multipartite computer virus discovered in October 1989 by Friðrik Skúlason. It is recognized as the first discovered multipartite virus because it infects both DOS .COM executable files and disk boot sectors. Its file-infection component was based on a modified Vienna virus, while its boot-sector component was derived from the Ping-Pong virus. The original author is unknown.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The first identified multipartite virus, using file and boot-sector infection mechanisms to make detection and removal more difficult.
Named 1980s-era malware (listed as part of a historical timeline). No behavior details provided in the content.
Computer virus (only referenced by name in the 1980s malware timeline; no additional details provided).
Hacking in the 1980s ... Malware ... Festering Hate ... Ghostball ... HyperCard viruses
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.