Skip to content

MyDoom

MyDoom, also known as Novarg, Mimail.R, and Shimgapi, is a Windows email worm that became one of the fastest-spreading mass-mailing malware outbreaks in Internet history after emerging in January 2004.

Profile source: Mallory opens in a new tab

MyDoom

Family profile

MyDoom, also known as Novarg, Mimail.R, and Shimgapi, is a Windows email worm that became one of the fastest-spreading mass-mailing malware outbreaks in Internet history after emerging in January 2004. It propagated primarily through socially engineered email messages that masqueraded as bounced or undelivered mail and carried malicious attachments disguised as harmless files, including compressed archives and executable formats. It also spread via peer-to-peer file sharing on KaZaa. Later activity showed the worm continued to circulate in malspam campaigns years after its initial outbreak.

Once executed, MyDoom harvested email addresses from infected systems, spoofed sender information, and generated large volumes of outbound email to continue self-propagation. Infected hosts also attempted direct SMTP delivery, contributing substantial global email disruption. The malware additionally opened infected machines to remote abuse and effectively surrendered control of compromised PCs to attackers, enabling their use as bots. MyDoom was widely associated with denial-of-service activity: the original variant targeted SCO, while a later variant targeted Microsoft. Reporting also describes MyDoom botnets being leveraged in broader disruptive operations, including Operation Troy against U.S. and South Korean websites, which has been linked to Lazarus in retrospective attribution reporting.

MyDoomโ€™s impact was amplified by its scale rather than destructive file wiping. It consumed bandwidth, disrupted mail infrastructure, and in some variants interfered with access to antivirus-related websites. Security reporting from the time estimated hundreds of thousands of infected machines across more than 200 countries. The malware remained notable long after 2004 because legacy variants continued to appear in spam-driven campaigns, demonstrating the persistence of old worm code in criminal ecosystems.

Capabilities

  • Ddos
  • Initial Access
  • Persistence
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 20, 2026
Last activity
Sep 24, 2026
Feed role
C2
Host form
19 IP / 0 hostnames

Leading locations

  • US10
  • IN6
  • AU1
  • BR1
  • JP1

Leading providers

  • Amazon.com, Inc.7
  • Microsoft Corporation5
  • AT&T Enterprises, LLC1
  • Charter Communications Inc1
  • Charter Communications, Inc1
  • Tulane University1

Infrastructure traits

  • Hosting 12

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Lazarus

2009 โ€“ Operation Troy This attack utilized the Mydoom and Dozer malware to launch a large-scale, but quite unsophisticated, DDoS attack against US and South Korean websites.

MITRE ATT&CK

MyDoom in ATT&CK

14 distinct techniques

Reporting

Research mentioning MyDoom

Jun 23
Darkatlas

Bluenoroff (APT38) Live Infrastructure Hunting - Darkatlas

North Korea-linked Lazarus Group and its financially motivated subgroup Bluenoroff/APT38 have been tied to long-running intrusions against banks, SWIFT-connected environments, cryptocurrency businesses, casinos, and other financial targets worldwide. Reporting from multiple investigations links the actors to operations including the Bangladesh Bank theft, compromises at Bancomext and Banco de Chile, and intrusions at banks in Southeast Asia and Europe. Investigators found that the group maintained access for months, compromised SWIFT Alliance infrastructure, patched SWIFT-related components to suppress integrity checks, harvested transaction data, and used keylogging, lateral movement, and anti-forensic measures to conceal activity and disrupt investigations. Researchers also documented recurring Lazarus tradecraft across these campaigns, including spear phishing, watering-hole attacks, brute force, exploitation of web and client vulnerabilities, fake-TLS command-and-control, service-based persistence, and reuse of malware families and tooling. Technical reporting connected incidents through shared backdoor design, tunneling tools, SWIFT-focused modules, and malware such as SQCSVC and SWPSVC, while newer infrastructure hunting identified phishing domains, linked IP space, and a macOS sample named localfile~.x64 communicating with 104.168.136.24. The combined findings reinforce attribution of these financially driven operations to the Lazarus ecosystem and show an adaptive capability spanning traditional banking networks and digital-asset platforms.

Dec 20
Proofpoint Threat Insight

North Korea Bitten by Bitcoin Bug: Financially motivated campaigns reveal new dimension of the Lazarus Group | Proofpoint US

Aug 23
Us Cert Gov Legacy

HIDDEN COBRA โ€“ North Koreaโ€™s DDoS Botnet Infrastructure

May 13
Baesystemsai Blogspot

BAE Systems Threat Research Blog: Cyber Heist Attribution

Apr 25
Baesystemsai Blogspot

BAE Systems Threat Research Blog: Two bytes to $951m

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.