Lehigh is an early MS-DOS file-infecting virus discovered in November 1987 at Lehigh University in the United States. It infected only COMMAND.COM and is described in the source material as the first memory-resident file infector and an early example of a cavity virus. Later research cited in the content indicates infected COMMAND.COM files increased in size by 555 bytes, despite early reports claiming no size increase. When an infected COMMAND.COM was executed, the virus remained resident in memory and infected previously uninfected COMMAND.COM files on other disks when users accessed those disks through normal DOS commands such as TYPE, COPY, or DIR. The malware altered the date of infected COMMAND.COM files and did not handle write-protect errors when attempting infection. It maintained an infection counter and, after four infections, activated a destructive payload that overwrote disk boot and FAT areas with contents from the BIOS. Because it only targeted disks containing COMMAND.COM and destroyed itself after activation, the content characterizes it as self-limiting; it also states that the initial outbreak apparently never spread beyond Lehigh University. No specific threat actor attribution or industry targeting beyond affected MS-DOS systems at universities and colleges is provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Early cavity virus that overwrites constant-filled portions of host files without increasing file length while preserving functionality.
A DOS file-infecting virus that infects COMMAND.COM, stays memory-resident, spreads to uninfected COMMAND.COM files on accessed disks, and after four infections overwrites boot and FAT areas of disks with BIOS contents.
An early cavity virus that overwrites unused constant-filled portions of host files without increasing file size.
Memory-resident file infector that specifically infected Command.com.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.