Last seven days
- First activity
- Sep 18, 2026
- Last activity
- Sep 18, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Sasser is a self-propagating Windows worm first released in 2004 that targeted vulnerable Windows 2000 and Windows XP systems by exploiting a flaw in the Local Security Authority Subsystem Service addressed by Microsoft bulletin MS04-011 (CVE-2003-0533).
Profile source: Mallory opens in a new tabSasser
Sasser is a self-propagating Windows worm first released in 2004 that targeted vulnerable Windows 2000 and Windows XP systems by exploiting a flaw in the Local Security Authority Subsystem Service addressed by Microsoft bulletin MS04-011 (CVE-2003-0533). Unlike email-borne worms common in the same era, Sasser spread autonomously over the network without user interaction by scanning for exposed hosts, exploiting the vulnerability remotely, and transferring itself from infected systems to newly compromised machines. Multiple variants appeared rapidly after the initial release.
A hallmark of Sasser infections was instability caused by crashes in the LSASS process, often resulting in forced system shutdowns or reboots. Some variants scanned so aggressively that they generated substantial network congestion, contributing to service disruption beyond the directly infected hosts. The worm caused widespread operational impact across government agencies, transportation providers, financial institutions, postal services, hospitals, media organizations, and other enterprises in multiple countries. Reported effects included unusable workstations, degraded network links, interrupted business operations, and temporary reversion to manual processes.
Sasser is strongly associated with German malware author Sven Jaschan, who admitted to creating the worm and was later convicted in Germany. Reporting has also linked the worm’s development to publicly available exploit code circulating at the time. The outbreak became one of the defining Windows worm incidents of the early 2000s and is frequently cited alongside Code Red, Slammer, Blaster, and Nimda as an example of large-scale vulnerability-driven malware propagation. Sasser also appeared in incident analyses involving industrial and critical infrastructure environments, where common worms exploiting commodity Windows systems contributed materially to operational disruptions.
C2 tracking
Derp observations, rolling seven-day window
Samples
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.