Festering Hate is an early Apple II ProDOS virus from 1988 and is widely described as the final and most destructive iteration of the CyberAIDS code base. It is among the first known Apple II ProDOS viruses. The malware infects ProDOS system files and propagates across available storage and memory on infected Apple II systems, including hard drives, floppy disks, and system memory. Its destructive logic activates after it can no longer locate additional uninfected files, at which point it destroys data on the host.
The virus family originated in the pirate software underground, where the payload was attached to cracked software, and later spread more broadly into mainstream Apple II communities. Festering Hate was also associated with spread through the shareware telecommunications application Zlink, leading some users at the time to suspect the application itself was acting as a Trojanized carrier. The malware is notable for combining self-replication with a highly destructive end state, distinguishing it from earlier Apple II malware such as Elk Cloner.
Festering Hate is closely linked to the earlier CyberAIDS variants, which appear to have evolved through minor code changes before culminating in the 1988 Festering Hate release. Contemporary anti-virus efforts on the Apple II platform focused heavily on CyberAIDS and Festering Hate, and Morgan Davis is credited with producing VirusMD to remediate the final strain. The malware has been associated in historical accounts with aliases including Rancid Grapefruit and Cereal Killer and with the Kool/Rad Alliance. Festering Hate remains primarily significant as a landmark example of destructive personal-computer malware from the late 1980s Apple II ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Festering Hate was the last iteration of the CyberAIDS code-base and seems to have bridged the virus from underground pirate BBS systems to the mainstream, by way of a shareware telecommunications application called Zlink. In fact, the original impression was that Zlink itself was nothing but a Trojan horse that delivered a viral payload.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Apple II wiper virus with destructive functionality that wiped storage media data blocks.
Hacking in the 1980s ... Malware ... Father Christmas ... Festering Hate ... Ghostball
Malware ... Festering Hate
Malware ... Festering Hate
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.