EXE_Bug is a historical PC boot-sector virus. The provided content states that it manipulates CMOS settings so the system appears to have no floppy drives present, causing the PC to bypass floppy boot attempts and boot from the infected hard disk instead. This behavior can fake out the boot process and interfere with recovery procedures that rely on booting from a clean floppy disk. No additional high-confidence details on infection vector, payload beyond CMOS tampering, associated threat actor, targeted industries, or specific indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PC boot-sector virus that alters CMOS settings as part of its payload.
PC virus that manipulates CMOS settings to interfere with clean floppy booting and keep the infected MBR active in memory.
PC virus that manipulates CMOS settings to interfere with clean floppy booting, causing users to believe they booted clean while the virus remains active in memory.
A PC boot sector virus that alters CMOS settings as part of its payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.