Skip to content

Computer Worm

Risk Level

A computer worm is standalone malware that self-replicates and spreads across networks without needing a host file or user interaction. It exploits network vulnerabilities, open shares, or protocols to propagate autonomously, often consuming bandwidth and system resources.

MilestoneYearDetails
Creeper1971First worm; ARPANET; “I’m the creeper, catch me if you can!”
Morris Worm1988First destructive worm; 6,000 machines (~10% of internet); first CFAA conviction
Code Red2001359,000 IIS machines in 14 hours
SQL Slammer2003Global in 10 minutes; 75,000 servers
Conficker2008Millions infected; massive botnet; domain generation
WannaCry2017200,000 systems in 150 countries; EternalBlue
1. SCANNING
└─ Network scan for vulnerable hosts (SYN scan, ICMP)
2. EXPLOITATION
└─ Exploit unpatched service / weak creds / open share
3. COPYING
└─ Copy self via exploited channel (SMB, FTP, email)
4. EXECUTION
└─ Execute on new host → cycle repeats
5. PAYLOAD DELIVERY
└─ Install backdoors, ransomware, DoS
6. C2 COORDINATION (advanced)
└─ Contact C2 for updated instructions
WormYearVulnerabilityImpact
Morris Worm1988Unix sendmail/finger6,000 machines; CERT/CC created
Code Red2001IIS .ida buffer overflow359K in 14 hrs
SQL Slammer2003SQL Server 200075K in 10 min
Conficker2008MS08-067Millions; DGA botnet
WannaCry2017EternalBlue (SMBv1)200K in 150 countries
  • ✅ Patch promptly — most worms exploit known, patched vulns
  • ✅ Network firewalls — restrict unnecessary connections
  • ✅ Network segmentation — VLANs, DMZs limit lateral movement
  • ✅ IDS/IPS — detect scanning and propagation
  • ✅ Disable unnecessary services and close unused ports
  • ✅ Strong passwords + MFA
  • ✅ Monitor for traffic spikes / connection volume anomalies
TechniqueIDDescription
Exploit Public-Facing ApplicationT1190Network service exploitation
Lateral Tool TransferT1570Self-copy to remote systems
Command and ControlT1071C2 communication