Twelve Tricks is a trojan horse reported around 1990 that targeted IBM-compatible computers running MS-DOS or PC DOS. It was distributed as a modified utility named CORETEST.COM, presented as a hard drive performance testing program. On infected systems, it altered the master boot record (described in the source as the partition sector). At each reboot, the trojan activated one of twelve different disruptive behaviors that affected hardware or interfered with normal system operation; the active behavior disappeared when power was cut, and a different one could appear on a later reboot. The malware also included destructive disk corruption logic: on each boot it had a 1 in 4096 chance of performing a low-level format of the active boot sector copy and the first FAT copy; otherwise, it modified one random word in the first sixteen FAT sectors, causing progressive file system damage. A Purdue University bulletin dated March 8, 1990 documented the trojan. The primary infection vector and notable artifact directly mentioned in the content is the trojanized CORETEST.COM file.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DOS Trojan horse delivered via a tampered CORETEST.COM utility. It alters the master boot record and on each reboot installs one of twelve disruptive 'tricks' affecting hardware or system operation. It can also randomly low-level format the active boot sector and first FAT copy or corrupt FAT sectors, causing progressive file system damage.
Named trojan referenced as detected by security researchers; no additional technical behavior described in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.