Skip to content

MyDoom

Mydoom, also known as Novarg, is a mass-mailing Windows worm first observed on 26 January 2004.

Profile source: Mallory opens in a new tab

MyDoom

Family profile

Mydoom, also known as Novarg, is a mass-mailing Windows worm first observed on 26 January 2004. It became one of the fastest-spreading e-mail worms of its era, infecting hundreds of thousands of systems globally and generating extremely large volumes of malicious mail traffic. It primarily targeted Microsoft Windows systems, especially contemporary desktop versions such as Windows 2000 and Windows XP.

Mydoom spread mainly through socially engineered e-mail messages that masqueraded as delivery failures, technical notices, or other plausible communications and carried executable attachments disguised as harmless files. It also harvested e-mail addresses from infected systems to continue propagation and attempted secondary spread through the KaZaA peer-to-peer file-sharing network. The worm used spoofed sender information, which amplified collateral e-mail disruption beyond directly infected hosts.

Once executed, Mydoom turned infected machines into remotely usable assets for malicious operators. Mydoom.A installed a backdoor that enabled remote control of compromised systems, while both major variants generated large amounts of outbound e-mail and could be used to hijack victim bandwidth and computing resources. The malware also included denial-of-service functionality: Mydoom.A was programmed to attack SCO Group, and Mydoom.B targeted Microsoft. Mydoom.B additionally altered local name-resolution behavior to block access to Microsoft and numerous security and antivirus sites, hindering remediation.

Mydoom has been associated with criminal botnet activity and was widely assessed as useful for spam operations and broader abuse of compromised hosts. Reporting has also linked at least one variant to the handle Diabl0 in the broader Mytob/Zotob malware ecosystem, though authorship of the family overall has remained unresolved. The worm’s impact was measured in major operational disruption, degraded e-mail service, and substantial economic losses across enterprises and internet infrastructure.

Capabilities

  • Ddos
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Spoofing

Reported operators

Threat actors

1 named in public reporting
Lazarus

This attack utilized the Mydoom and Dozer malware to launch a large-scale, but quite unsophisticated, DDoS attack against US and South Korean websites.

MITRE ATT&CK

MyDoom in ATT&CK

9 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.