The Mydoom e-mail worm, also tracked as Novarg and W32/MyDoom, spread at record speed across the internet, infecting hundreds of thousands of computers and generating millions of malicious messages in more than 200 countries. Security firms said the worm relied on social engineering rather than advanced exploitation, arriving as spoofed e-mails that appeared to be bounced or undelivered messages and carrying executable attachments disguised as harmless text or ZIP files. The outbreak was severe enough that the U.S. Department of Homeland Security activated its cyber alert system, while Microsoft and SCO Group each offered $250,000 rewards for information leading to the author’s arrest.
The worm also converted infected systems into denial-of-service bots. Mydoom.A was programmed to attack SCO Group, while Mydoom.B shifted its focus to Microsoft and additionally altered the Windows Hosts file to block access to antivirus vendors’ websites, complicating cleanup for victims. By early February, mail-filtering data showed the outbreak was beginning to fade after peaking in late January, and monitoring indicated the Microsoft-targeting variant caused little measurable disruption because it spread less widely than the original strain.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
By 3 February, monitoring data showed Mydoom infections were falling after peaking on 28 January. Variant B's planned attack on Microsoft appeared to have little effect, with only minor response-time changes observed and no clear evidence of significant disruption.
The original Mydoom variant was programmed to flood SCO Group's website with traffic, disrupting access. Reporting described the attack as scheduled for February 1 and associated it with infected machines acting as bots.
Researchers and mail-filtering firms concluded that Mydoom had become the fastest-spreading email virus observed at the time. It ultimately infected systems in 214 countries and generated more than 21 million intercepted copies.
Microsoft published security guidance describing the Mydoom.A and Mydoom.B worm variants. The guidance noted that variant B redirected the denial-of-service objective toward Microsoft and altered infected systems to block access to antivirus websites.
The U.S. Department of Homeland Security activated its new cyber alert system in response to the Mydoom outbreak. The move reflected concern over the worm's rapid spread and its built-in denial-of-service capabilities.
SCO Group and Microsoft each offered $250,000 rewards for information leading to the arrest of the worm's author. The offers came as Mydoom's denial-of-service components targeted SCO and threatened Microsoft.
The Mydoom email worm, also known as Novarg, began propagating rapidly through spoofed messages carrying executable attachments disguised as harmless files. Security firms reported massive volumes of malicious email and widespread infections across hundreds of thousands of computers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
abcnews.go.com
Open sourceweb.archive.org
Open sourcenews.bbc.co.uk
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.