One_Half is a DOS-era polymorphic multipartite virus that became common after appearing in 1994. It is notable for gradually encrypting the infected hard drive inward from the end of the disk toward the beginning, encrypting two additional tracks at each boot. The malware infects the master boot record, and the FAQ material specifically warns that improper cleanup with FDISK /MBR can cause irreversible data loss because decryption metadata may be stored only in the MBR. Historical source material also describes One_Half as among the first viruses known to have encrypted affected files. High-confidence context associates it with PC/DOS environments and with disk/boot infection behavior rather than modern network propagation. No specific threat actor, industry targeting, or concrete IOC set is provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Polymorphism involves encrypted viruses where the decryption routine code is variable.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MBR virus that progressively encrypts portions of the hard drive and stores encrypted-area size information only in the MBR.
An early file-infecting virus noted for encrypting affected files.
An MBR-infecting virus that progressively encrypts portions of the hard drive and stores decryption state in the MBR.
Common polymorphic multipartite virus.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.