A newly disclosed Microsoft Windows Plug and Play buffer overflow vulnerability, tracked as VU#998653 and addressed by Microsoft's MS05-039 patch, was rapidly weaponized into multiple worms including Zotob, RBot, SD-Bot, and related IRC bot variants. The malware primarily targeted unpatched Windows 2000 systems, disrupting high-profile organizations such as CNN, The New York Times, ABC News, and parts of Capitol Hill. Security researchers said the outbreak drew intense attention because of the prominent victims, but Internet monitoring groups and Microsoft assessed it as more localized than an Internet-wide epidemic, with Windows XP largely unaffected and patched or firewalled systems better protected.
The incident showed how quickly exploit code could follow a patch release, with public exploits appearing within days and Zotob detected shortly afterward as attackers folded the flaw into existing bot malware. Antivirus vendors and responders urged organizations to apply patches, update signatures, isolate infected hosts, and use removal tools for the growing list of Zotob variants. Investigators later detained Farid Essebar in Morocco and Atilla Ekici in Turkey in connection with the worm campaign, while researchers said the arrests also exposed a broader underground trade in compromised PCs and shared malware source code that enabled continued variant development.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Follow-up reporting said security researchers connected the detained Zotob suspect's 'Diabl0' signature to more than 20 malware samples, including Mytob and MyDoom variants. Analysts noted that multiple actors likely continued producing related variants even after the arrests.
Authorities detained Farid Essebar in Morocco and Atilla Ekici in Turkey in connection with the Zotob worm case. Investigators alleged Essebar, using the handle 'Diabl0,' created Zotob for Ekici, and researchers linked the alias to numerous other malware samples.
Researchers from vendors including Trend Micro, McAfee, F-Secure, Sophos, and Symantec reported that several malware families and variants—such as Zotob, RBot, SD-Bot, IRC-Bot, CodBot, and Bozori—were exploiting the same flaw. Analysts and Microsoft assessed the incident as serious but relatively localized rather than a broad Internet-wide catastrophe.
Symantec published a dedicated W32.Zotob removal tool and updated it repeatedly between August 15 and August 26 to detect and remove additional Zotob variants. The company advised disconnecting infected machines, restricting shared folders, and running the tool with administrative privileges.
Multiple worms exploiting the Windows vulnerability infected high-profile organizations including CNN, The New York Times, and reportedly ABC News. CNN said its Windows 2000-based network disruption was severe enough to force programming changes, while other reports also cited impacts on Capitol Hill systems.
F-Secure discovered Zotob, one of several worms exploiting the Windows Plug and Play vulnerability. Zotob became the most prominent malware family associated with the outbreak.
As exploit activity increased, the SANS Internet Storm Center raised its InfoCon alert level to yellow, signaling elevated concern around attacks targeting the newly disclosed Windows flaw. This reflected growing evidence of active exploitation attempts.
Exploit code for the Plug and Play vulnerability began circulating within days of Microsoft's patch release, enabling bot and worm authors to weaponize the flaw quickly. Later reporting cited this rapid exploit availability as a key factor in the ensuing outbreak.
Microsoft released security bulletin MS05-039 for a buffer overflow vulnerability in Windows Plug and Play that affected older Windows systems, including Windows 2000. CERT/CC also published advisory VU#998653 on the issue.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
8 references tracked. Mallory keeps watching after this page renders.
web.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourcenews.bbc.co.uk
Open sourcenews.bbc.co.uk
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourcekb.cert.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.