Last seven days
- First activity
- Sep 20, 2026
- Last activity
- Sep 24, 2026
- Feed role
- C2
- Host form
- 19 IP / 0 hostnames
MyDoom, also known as Novarg, Mimail.R, and Shimgapi, is a Windows email worm that became one of the fastest-spreading mass-mailing malware outbreaks in Internet history after emerging in January 2004.
Profile source: Mallory opens in a new tabMyDoom
MyDoom, also known as Novarg, Mimail.R, and Shimgapi, is a Windows email worm that became one of the fastest-spreading mass-mailing malware outbreaks in Internet history after emerging in January 2004. It propagated primarily through socially engineered email messages that masqueraded as bounced or undelivered mail and carried malicious attachments disguised as harmless files, including compressed archives and executable formats. It also spread via peer-to-peer file sharing on KaZaa. Later activity showed the worm continued to circulate in malspam campaigns years after its initial outbreak.
Once executed, MyDoom harvested email addresses from infected systems, spoofed sender information, and generated large volumes of outbound email to continue self-propagation. Infected hosts also attempted direct SMTP delivery, contributing substantial global email disruption. The malware additionally opened infected machines to remote abuse and effectively surrendered control of compromised PCs to attackers, enabling their use as bots. MyDoom was widely associated with denial-of-service activity: the original variant targeted SCO, while a later variant targeted Microsoft. Reporting also describes MyDoom botnets being leveraged in broader disruptive operations, including Operation Troy against U.S. and South Korean websites, which has been linked to Lazarus in retrospective attribution reporting.
MyDoomโs impact was amplified by its scale rather than destructive file wiping. It consumed bandwidth, disrupted mail infrastructure, and in some variants interfered with access to antivirus-related websites. Security reporting from the time estimated hundreds of thousands of infected machines across more than 200 countries. The malware remained notable long after 2004 because legacy variants continued to appear in spam-driven campaigns, demonstrating the persistence of old worm code in criminal ecosystems.
C2 tracking
Derp observations, rolling seven-day window
Samples
1cfc72b71019d4f49d594bd8920db949f2ed224be12a3e51689d3c38cd581367 56b960d8208982d171181d7b35735ecdc4cabf4207badc4cec037710858776c9 5f539b424e0a6215acde01407d4f4c2d4dc995d2120d24687f4e842dce25f4de 741ee173ea3d1b4ed815b7f387c6c948e0bf7922efe0573fbf5bc86cfab88f66 977f74d78a0257b21582dd65e2331e48b7eed70639693787b67e607d9a7bc1ea 9a127f4180f45511947caaad12120824da087c56cf299648553ff280895343ab 0af608dab692d28cbd7c2b978dd2c9451937b2b35e8130d77a2de3a96b02a055 1c826d5f4e740e24b70085b802420beee297c7ebd85f1f70bbd1bf3c33fa83d7 450b2184e5f550dce3ec6793f272cd93ea45739243cab0211e2f8533b268cda0 c9e0922d4c39a727a2fd65e2157775cac867c0267cd591e3a3e1a188cf139b14 Reported operators
2009 โ Operation Troy This attack utilized the Mydoom and Dozer malware to launch a large-scale, but quite unsophisticated, DDoS attack against US and South Korean websites.
MITRE ATT&CK
Reporting
North Korea-linked Lazarus Group and its financially motivated subgroup Bluenoroff/APT38 have been tied to long-running intrusions against banks, SWIFT-connected environments, cryptocurrency businesses, casinos, and other financial targets worldwide. Reporting from multiple investigations links the actors to operations including the Bangladesh Bank theft, compromises at Bancomext and Banco de Chile, and intrusions at banks in Southeast Asia and Europe. Investigators found that the group maintained access for months, compromised SWIFT Alliance infrastructure, patched SWIFT-related components to suppress integrity checks, harvested transaction data, and used keylogging, lateral movement, and anti-forensic measures to conceal activity and disrupt investigations. Researchers also documented recurring Lazarus tradecraft across these campaigns, including spear phishing, watering-hole attacks, brute force, exploitation of web and client vulnerabilities, fake-TLS command-and-control, service-based persistence, and reuse of malware families and tooling. Technical reporting connected incidents through shared backdoor design, tunneling tools, SWIFT-focused modules, and malware such as SQCSVC and SWPSVC, while newer infrastructure hunting identified phishing domains, linked IP space, and a macOS sample named localfile~.x64 communicating with 104.168.136.24. The combined findings reinforce attribution of these financially driven operations to the Lazarus ecosystem and show an adaptive capability spanning traditional banking networks and digital-asset platforms.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.