NetSky is a prolific family of mass-mailing computer worms targeting Microsoft Windows systems that first emerged in February 2004. It spread primarily through email messages carrying malicious attachments and relied on user execution of the attachment to begin infection. Once active, NetSky harvested email addresses from the compromised host and mailed copies of itself to discovered contacts, enabling rapid self-propagation across organizations and consumer systems.
The family became one of the most prevalent email-borne malware threats of the mid-2000s, with numerous variants appearing in quick succession. NetSky is widely attributed to Sven Jaschan, a German malware author who also confessed to creating Sasser and at least some NetSky variants. Several variants contained taunting messages aimed at the authors of rival malware families, especially Bagle and Mydoom, and some variants attempted to remove those worms from infected systems. This rivalry contributed to a highly visible malware "war" marked by frequent new releases and mutual interference among competing worm families.
Observed behavior associated with NetSky includes address harvesting, autonomous mass-mailing after execution, and user-visible nuisance effects such as beeping on specified dates in some variants. The malware affected Windows environments broadly and achieved sustained global prevalence; the NetSky.P variant remained one of the most widespread email-borne viruses until late 2006. NetSky is historically significant as a defining example of early-2000s Windows email worms and of the competitive dynamics among malware authors during that period.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware 2004 Bagle NetSky Sasser Mydoom
2004 Bagle NetSky
Netsky is mentioned only as a historical example of rival malware authors engaging in a turf war.
Malware 2004 NetSky
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.