WANK (Worms Against Nuclear Killers) was a politically motivated computer worm that spread through DECnet-connected DEC VMS/VAX systems in October 1989. Written in DIGITAL Command Language, it propagated pseudo-randomly between DECnet nodes, abusing weak or default account credentials and inadequate network segmentation. It affected research and government networks including NASA's Space Physics Analysis Network, the U.S. Department of Energy's High Energy Physics Network, CERN, and Riken. WANK displayed anti-nuclear and anti-war messages, including a claim that systems had been “officially WANKed,” and simulated file deletion without actually deleting files in its initial form. It also sent disruptive messages to users. A subsequent related variant, commonly called OILZ, overcame some early countermeasures, could access unprotected accounts, and changed account passwords, locking out legitimate users. Defenders developed anti-WANK and WANK_SHOT utilities, but eradication across affected DECnet networks took weeks. WANK is widely regarded as an early prominent example of hacktivist malware; its authorship was never conclusively established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historical virus mentioned in a list without further technical detail.
A DECnet/VAX worm structurally similar to Father Christmas that spread via random node searches and weak/default credentials such as DECNET, SYSTEM, and FIELD. The first version mainly caused psychological disruption with fake file deletions and prank messages; the second version rewrote passwords and locked users out of compromised systems.
Hacking in the 1980s ... Malware ... Virdem ... WANK
Malware ... WANK
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.