The ILOVEYOU or LoveLetter email worm spread rapidly through Windows PCs by arriving as an attachment named LOVE-LETTER-FOR-YOU.TXT.vbs with the subject line ILOVEYOU, then mailing itself to Microsoft Outlook contacts and propagating through mIRC. Security analysis from F-Secure said the Visual Basic Script malware modified the Windows registry for persistence, changed Internet Explorer settings, overwrote scripts, images, and audio files across local and remote drives, and downloaded a password-stealing trojan that exfiltrated cached Windows and RAS credentials through smtp.super.net.ph to mailme@super.net.ph.
Reporting tied the worm's suspected origin to the Philippines and focused on Filipino programmer Onel de Guzman, who was linked to the outbreak and later spoke publicly without expressing remorse, describing his actions in terms of a "license to hack." The case also highlighted legal shortcomings at the time: Philippine authorities moved to drop charges because existing law did not clearly criminalize the conduct, underscoring how one of the first major global email-worm incidents outpaced national cybercrime statutes even as it caused widespread disruption and data loss.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Years after the outbreak, reporting described the alleged Love Bug author as expressing no apology or remorse for the damage caused by the worm. The interview served as a retrospective public response tied to the original incident.
A Filipino man linked to the Love Bug case gave a public interview discussing his activities and presenting himself as having a "license to hack." The interview marked a notable public statement from a figure associated with the worm's creation.
Reports indicated that authorities in the Philippines were set to drop charges related to the ILOVEYOU virus case, reflecting legal difficulties in prosecuting the incident under the country's laws at the time.
Technical analysis revealed the worm modified the Windows registry for persistence, changed Internet Explorer settings, and downloaded an additional trojan that stole cached Windows and RAS passwords. The stolen credentials were exfiltrated via email through smtp.super.net.ph to a mailbox associated with the campaign.
The LoveLetter, or ILOVEYOU, worm was discovered spreading widely in the wild, propagating through Microsoft Outlook with the subject line "ILOVEYOU" and a malicious VBS attachment. It also spread through mIRC and caused widespread file overwriting and data loss on infected systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
theregister.co.uk
Open sourcenytimes.com
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourcef-secure.com
Open sourcezdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.