Flip is a historical DOS-era virus identified in the provided content as probably the first successful multipartite virus, and it is also described as polymorphic. As a multipartite virus, it infected more than one target type, consistent with DOS malware that spread via both files and boot-related structures. The content specifically notes a logic error in Flip, likely due to its author only understanding DOS 3.x hard-disk partitioning schemes. As a result, infection could make large hard-disk partitions appear to shrink to under 32 MB, leading victims to believe that a large part of the disk had disappeared. The supplied material places Flip in the 1990 period of PC malware evolution. No specific threat actor, industry targeting, or concrete indicators of compromise beyond the partition-size anomaly are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
Polymorphism involves encrypted viruses where the decryption routine code is variable.
If a boot sector virus has infected your diskette, the virus code will be contained in the buffer... The use of DIR will not infect a clean system... Mac users with system software prior to version 7.0 should be aware of a greater threat... A common Mac virus, WDEF, uses this infection path... At least one Amiga virus, Saddam, attaches itself to Disk Validator to help it spread.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Virus with a flawed infection routine that corrupts partition geometry information, potentially making large portions of a hard disk appear to disappear.
Virus with a flawed infection routine that corrupts partition geometry information on larger DOS partitions, making much of the disk appear to disappear.
A named virus referenced in relation to apparent loss of hard disk space.
Polymorphic multipartite virus considered the first successful multipartite virus.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.