MyDoom, also known as Novarg, Mimail.R, and Shimgapi, is a Windows email worm that became one of the fastest-spreading mass-mailing malware outbreaks in Internet history after emerging in January 2004. It propagated primarily through socially engineered email messages that masqueraded as bounced or undelivered mail and carried malicious attachments disguised as harmless files, including compressed archives and executable formats. It also spread via peer-to-peer file sharing on KaZaa. Later activity showed the worm continued to circulate in malspam campaigns years after its initial outbreak.
Once executed, MyDoom harvested email addresses from infected systems, spoofed sender information, and generated large volumes of outbound email to continue self-propagation. Infected hosts also attempted direct SMTP delivery, contributing substantial global email disruption. The malware additionally opened infected machines to remote abuse and effectively surrendered control of compromised PCs to attackers, enabling their use as bots. MyDoom was widely associated with denial-of-service activity: the original variant targeted SCO, while a later variant targeted Microsoft. Reporting also describes MyDoom botnets being leveraged in broader disruptive operations, including Operation Troy against U.S. and South Korean websites, which has been linked to Lazarus in retrospective attribution reporting.
MyDoom’s impact was amplified by its scale rather than destructive file wiping. It consumed bandwidth, disrupted mail infrastructure, and in some variants interfered with access to antivirus-related websites. Security reporting from the time estimated hundreds of thousands of infected machines across more than 200 countries. The malware remained notable long after 2004 because legacy variants continued to appear in spam-driven campaigns, demonstrating the persistence of old worm code in criminal ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2009 – Operation Troy This attack utilized the Mydoom and Dozer malware to launch a large-scale, but quite unsophisticated, DDoS attack against US and South Korean websites.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
They want to steal your bandwidth--take over your computer, basically--to use your PC for nefarious purposes, so it can't be tracked back to theirs.
Various mail servers over TCP port 25 - SMTP and attempted SMTP traffic ... see a full malspam message sent from my infected Windows host
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in passing as one of the notable early worms.
The ILOVEYOU virus walked so that MyDoom could run.
Malware 2004 ... Sasser Mydoom
MyDoom is referenced as a malware family for which ClamAV had a hardcoded/heuristic detection that was disabled due to false positives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.