Bagle, also widely known as Beagle, is a large family of mass-mailing Windows worms that emerged in early 2004 and later became associated with a substantial spam-sending botnet. Early variants propagated through executable email attachments, harvested addresses from local files and the Windows Address Book, and used their own SMTP routines to send copies of themselves to new victims. The malware employed simple social-engineering lures, including disguising attachments as benign files, and some variants launched a legitimate Windows program on execution to reduce suspicion.
Once run, Bagle copied itself into the Windows system directory, established persistence through Windows registry Run entries, and opened a backdoor that allowed remote access to the infected host. Documented behavior includes listening on variant-specific TCP ports, contacting predefined web resources, and in some cases downloading and executing additional malware components. The family therefore combined worm-like self-propagation with backdoor functionality and later botnet use.
Bagle targeted Microsoft Windows systems and spawned a very large number of variants during 2004 and 2005. Several variants were programmed with stop-spreading dates, and newer releases could update older infections. Bagle became notable not only for its prevalence but also for its public rivalry with the Netsky worm family, with both families reportedly attempting to remove one another from infected systems and containing insulting messages aimed at rival authors. Historically, Bagle was also tracked as a major spambot, at times accounting for a significant share of global spam volume.
Bagle is regarded as a historically significant early-2000s malware family because it blended mass-mailing propagation, persistence, remote-control backdoor access, and spam-bot operations at scale.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Early January saw a rise in activity from both the Lethic and Bagle spambots... it is currently responsible for about eight to ten per cent of the spam in our traps... The Bagle 2 botnet was only responsible for around 1.9 per cent of spam sent.
The attachment is an executable file with a random file. Once the user executes the file, the virus mails itself to all of the names found on the users hard drive | The new variant arrives in an e-mail with a spoofed sending address and a subject line that contains the term “ID” followed by a string of random characters. The text of the message simply says: “Yours ID” followed by another bunch of random characters. The attachment is an executable file with a random file.
When a user executes Bagle's attachment, the virus puts copies of itself called "bbeagle.exe" into the Windows System folders and adds the following registry keys to allow it to run when the system is started: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, "d3update.exe" = "%system%\bbeagle.exe"
When a user executes Bagle's attachment, the virus puts copies of itself called "bbeagle.exe" into the Windows System folders and adds the following registry keys to allow it to run when the system is started: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, "d3update.exe" = "%system%\bbeagle.exe"
Once running, Bagle will attempt to connect with a PHP script on a series of internally hard-coded web sites.
When the worm is started it connects to a list of predefined web servers and tries to access a PHP file with certain parameters. One of the parameters is the TCP port where the backdoor is listening which suggests that this functionality is used to collect the addresses of infected computers.
Using its own SMTP engine Bagle sends messages with infected attachments to the collected addresses. The SMTP engine uses direct Mail eXchange (MX) lookup on the target domain so it does not depend on email settings of the infected computer.
The virus also listens on port 6777 for a malicious user to connect.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bagle is mentioned as another malware family linked to a lookalike domain found during infrastructure pivoting, suggesting possible shared infrastructure or naming patterns.
Malware 2004 Bagle NetSky Sasser Mydoom
Worm malware mentioned as appearing in communicating files tied to an IP uncovered during lookalike-domain pivoting, suggesting possible shared or overlapping infrastructure.
Bagle is cited as an early example of the 'MalWare 2.0' model of complex malicious programs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.