Virdem is an MS-DOS file-infecting virus described in the content as the first file virus for MS-DOS and one of the oldest MS-DOS viruses. It was written by Ralf Burger in 1986 in Germany as a demonstration program for a Chaos Computer Club conference, and was distributed at a Chaos Computer Club conference in Hamburg in December 1986. Virdem infects only .COM files by copying itself and attaching to them. It is characterized as a direct-action virus that does not spread quickly: when an infected file is executed, the next uninfected .COM program becomes infected. Technically, it overwrites the host program with its own code while saving the original program at the end of the file. Infected small COM files under 11 KB grow by 2559 bytes, while larger infected COM files grow by 1336 bytes. The malware is described as fairly harmless because it clearly announces its presence. Infected programs prompt the user to guess a number between 0 and n matching the virus generation number plus one; if the guess is correct, the original program runs, and if incorrect, the program exits. Additional behaviors noted in the content include failure to intercept interrupt 24h, which can cause an "Abort, Retry, Ignore" message on write-protected disks; changing read-only files to read/write for infection without restoring the read-only attribute; and the presence of two NOP instructions at the beginning of infected files. No specific threat actor association beyond author Ralf Burger is stated in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named 1980s-era malware (listed as part of a historical timeline). No behavior details provided in the content.
Computer virus (only referenced by name in the 1980s malware timeline; no additional details provided).
Early MS-DOS file-infector that self-replicates by attaching to .COM executables. It overwrites the host with its own code, stores the original program at the end of the file, and infects the next uninfected .COM executed. It is described as fairly harmless and announces its presence (e.g., prompts the user to guess a number tied to the virus generation).
Hacking in the 1980s ... Malware ... Stoned ... Virdem ... WANK
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.