WDEF is a historical Macintosh virus identified in the provided content as a common Mac virus. It used a pre-System 7.0 Macintosh infection path in which infected resources could be executed while the system was building the desktop view of a diskette. The content specifically states that Macintosh systems prior to version 7.0 could execute infected resources loaded from a diskette Desktop file during desktop-building operations, and that WDEF used this resource-loading behavior to spread. No specific threat actor, industry targeting, payload details, or indicators of compromise are provided in the content beyond its association with this Macintosh-specific infection vector.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Macintosh virus that spreads via infected system resources loaded from a diskette Desktop file on pre-System 7 Macs.
Macintosh virus that spreads via infected system resources loaded from a diskette Desktop file on pre-7.0 Mac system software.
Macintosh virus that spreads via infected system resources in the Desktop file on pre-7.0 Mac system software, causing execution when the resource is later loaded.
A Macintosh virus that spreads via infected resources loaded during desktop handling on pre-System 7 Macs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.