Skip to content

Sasser

Sasser is a self-propagating Windows worm first released in 2004 that targeted vulnerable Windows 2000 and Windows XP systems by exploiting a flaw in the Local Security Authority Subsystem Service addressed by Microsoft bulletin MS04-011 (CVE-2003-0533).

Profile source: Mallory opens in a new tab

Sasser

Family profile

Sasser is a self-propagating Windows worm first released in 2004 that targeted vulnerable Windows 2000 and Windows XP systems by exploiting a flaw in the Local Security Authority Subsystem Service addressed by Microsoft bulletin MS04-011 (CVE-2003-0533). Unlike email-borne worms common in the same era, Sasser spread autonomously over the network without user interaction by scanning for exposed hosts, exploiting the vulnerability remotely, and transferring itself from infected systems to newly compromised machines. Multiple variants appeared rapidly after the initial release.

A hallmark of Sasser infections was instability caused by crashes in the LSASS process, often resulting in forced system shutdowns or reboots. Some variants scanned so aggressively that they generated substantial network congestion, contributing to service disruption beyond the directly infected hosts. The worm caused widespread operational impact across government agencies, transportation providers, financial institutions, postal services, hospitals, media organizations, and other enterprises in multiple countries. Reported effects included unusable workstations, degraded network links, interrupted business operations, and temporary reversion to manual processes.

Sasser is strongly associated with German malware author Sven Jaschan, who admitted to creating the worm and was later convicted in Germany. Reporting has also linked the worm’s development to publicly available exploit code circulating at the time. The outbreak became one of the defining Windows worm incidents of the early 2000s and is frequently cited alongside Code Red, Slammer, Blaster, and Nimda as an example of large-scale vulnerability-driven malware propagation. Sasser also appeared in incident analyses involving industrial and critical infrastructure environments, where common worms exploiting commodity Windows systems contributed materially to operational disruptions.

Capabilities

  • Initial Access
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 18, 2026
Last activity
Sep 18, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • DE1

Leading providers

  • ARVANCLOUD GLOBAL TECHNOLOGIES L.L.C1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

Sasser in ATT&CK

7 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.