Stoned is an early IBM PC-compatible boot-sector virus, apparently created in New Zealand in 1987 and widespread during the late 1980s and early 1990s. It infects floppy-disk boot sectors and hard-disk master boot records, allowing execution before DOS starts. On an infected boot, it becomes memory resident by reserving conventional memory and hooks BIOS disk I/O services. This enables it to infect previously clean floppy disks when they are accessed. Stoned preserves the hard-disk partition table and stores displaced boot code elsewhere on the disk, but its use of fixed storage locations can cause accidental data corruption when those locations are reused by the filesystem. The original variant intermittently displays the boot-time message “Your PC is now Stoned!” and contains an unused marijuana-related text string. Stoned is historically notable as an early master-boot-record infector and as the progenitor of variants including Michelangelo; unlike Michelangelo, the original Stoned variant was comparatively simple and did not include a date-triggered disk-wiping payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
It writes itself to floppies and hard disks (Master Boot Record) and backs up the original bootloader it overwrites.
As the name suggests, viruses of this type infect the bootsector of an operating system's boot disk. The orignal bootsector of an infected disk has been copied elsewhere on the disk and the virus has been placed in the bootsector.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
A resident virus installs itself somewhere in memory (RAM) the first time an infected program is executed, and thereafter infects other programs when they are executed...
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
A resident virus installs itself somewhere in memory (RAM) the first time an infected program is executed, and thereafter infects other programs when they are executed...
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
Another point was that files could vanish - this is because the back up is done for floppies on head 1 sector 3, which could be occupied by FAT root directory.
The code checks the system clock, and on March 6th, it enters an endless loop of filling up the sectors on the disk with the bootsector.
It writes itself to floppies and hard disks (Master Boot Record) and backs up the original bootloader it overwrites.
As the name suggests, viruses of this type infect the bootsector of an operating system's boot disk. The orignal bootsector of an infected disk has been copied elsewhere on the disk and the virus has been placed in the bootsector.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historical virus mentioned in a list without further technical detail.
Named 1980s-era malware (listed as part of a historical timeline). No behavior details provided in the content.
Boot-sector virus (only referenced by name in the 1980s malware timeline; no additional details provided).
Hacking in the 1980s ... Malware ... Scores ... Stoned ... Virdem
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.