LoveLetter, widely known as ILOVEYOU, is a mass-mailing VBScript worm found globally in the wild on 2000-05-04 and assessed in the provided content as likely originating from the Philippines. It propagates primarily via Microsoft Outlook by sending itself to every contact in each address book using the subject "ILOVEYOU," the body text "kindly check the attached LOVELETTER coming from me," and the attachment "LOVE-LETTER-FOR-YOU.TXT.vbs." It sends itself only once per recipient and records that state in the registry. The worm also spreads through mIRC by creating LOVE-LETTER-FOR-YOU.HTM in the Windows System directory and replacing script.ini. On execution, it copies itself into the Windows System directory as MSKernel32.vbs and as LOVE-LETTER-FOR-YOU.TXT.vbs, and adds registry entries for persistence. It modifies the Internet Explorer home page to point to WIN-BUGSFIX.exe; if that file is downloaded, it is added to startup. The downloaded component is described as a password-stealing trojan. That trojan persists as \Windows\System\WINFAT32.EXE, creates a hidden window titled "BAROK...," attempts to remove registry policy settings related to HideSharePwds and DisablePwdCaching, loads MPR.DLL, calls WNetEnumCashedPasswords to obtain cached passwords, steals RAS and cached Windows passwords, and exfiltrates them via smtp.super.net.ph to mailme@super.net.ph with subject "Barok... email.passwords.sender.trojan." Beyond propagation, LoveLetter searches local and remote drives and overwrites .vbs and .vbe files with its own code, and replaces .js, .jse, .css, .wsh, .sct, .hta, .jpg, .jpeg, .mp3, and .mp2 files with similarly named .vbs files, deleting originals in some cases and hiding originals for some audio files. The content also notes a 2001 variant of the LoveLetter worm that contained a dropper routine for the CIH virus.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The virus infected about 45 million machines in 24 hours, leaving email systems overwhelmed.
Then the worm uses Outlook to mass mail itself to everyone in each address book.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A well-known email worm cited as a historical comparison for operational impact on corporate email systems.
Email/VBS worm referenced as having a variant that acted as a dropper for CIH, helping re-circulate CIH in 2001.
Since Melissa's romp over two years ago, the Internet has hosted hundreds of other viruses, from LoveLetter to Code Red and Sircam.
An email-borne worm/virus referenced as an example of self-propagating malicious code that spreads by sending itself to others.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.