Bomber, also known as Commander Bomber, is a DOS polymorphic, memory-resident computer virus and a file and boot infector. It is attributed in the cited material to the Bulgarian virus author Dark Avenger, with Vesselin Bontchev referenced as the source for that attribution. Bomber is notable for introducing the "patchy infection" technique: instead of appending a full virus body to an executable and changing the entry point, it inserts multiple fragments of its code into random locations within a file, with those fragments transferring control to each other through various mechanisms. This approach is described as making antivirus detection more difficult because scanners may need to inspect the entire file. The content also states that Bomber was not encrypted, was approximately 4096 bytes in size, and contained the embedded text "COMMANDER BOMBER WAS HERE [DAME] [DAME]." The material further notes that the patchy infection technique introduced in Bomber was later associated with OneHalf.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Contrary to the usual method of infecting executables (which is to append virus body to the executable and to change the entry point), it inserts several fragments ("patches") of its code in random places inside the file. These fragments transfer control to each other using various mechanisms. The method of infection makes the detection of the virus difficult by anti-virus programs
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the virus that introduced the 'patchy infection' technique later implemented by OneHalf.
A DOS polymorphic, memory-resident virus that infects files and boot sectors using a 'patchy infection' technique, inserting code fragments in random places inside files to hinder antivirus detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.