Michelangelo, also known as March 6, is a DOS boot-sector virus and a variant of the Stoned virus family. First discovered in Australia in February 1991, it infects the master boot record of IBM PC-compatible hard disks and boot sectors of floppy disks, operating below DOS through BIOS-level disk services. An infected system can propagate the virus to floppy media when the media is written or accessed through infected disk routines. Michelangelo remains dormant until March 6, the birthday of the Renaissance artist for which it was named. On affected AT and PS/2-class systems, its payload overwrites the initial sectors of the hard disk, rendering boot and user data inaccessible or unrecoverable without specialized recovery. The malware relocates original boot records to other disk sectors, which can itself create disk corruption risks. Michelangelo received substantial international attention in 1992 after infected products were inadvertently distributed by some manufacturers. Its author is unknown.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
As the name suggests, viruses of this type infect the bootsector of an operating system's boot disk. The orignal bootsector of an infected disk has been copied elsewhere on the disk and the virus has been placed in the bootsector.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
A resident virus installs itself somewhere in memory (RAM) the first time an infected program is executed, and thereafter infects other programs when they are executed...
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
A resident virus installs itself somewhere in memory (RAM) the first time an infected program is executed, and thereafter infects other programs when they are executed...
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
The code checks the system clock, and on March 6th, it enters an endless loop of filling up the sectors on the disk with the bootsector.
As the name suggests, viruses of this type infect the bootsector of an operating system's boot disk. The orignal bootsector of an infected disk has been copied elsewhere on the disk and the virus has been placed in the bootsector.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historical virus mentioned in a list without further technical detail.
The content includes a 'Malware' list under 'Hacking in the 1990s' that names: 'CIH, Happy99, Hare, KAK, Melissa, Michelangelo, Staog'.
Timeline ... Malware ... CIH ... Happy99 ... Hare ... KAK ... Melissa ... Michelangelo ... Staog
A destructive virus known for wiping the master boot record on March 6.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.