{
  "family": "mytob",
  "sample_count": 1,
  "category": "backdoor",
  "description": "<h3>Executive Summary</h3>\nMytob is a highly prolific and historically significant mass-mailing worm and botnet agent that first emerged in the mid-2000s. Based largely on the source code of the notorious MyDoom worm, Mytob combined rapid email-based propagation with backdoor functionality, creating massive botnets that severely disrupted global email infrastructure and corporate networks.\n\n<h3>Propagation and Technical Mechanisms</h3>\nMytob was engineered for aggressive self-replication, utilizing multiple vectors to compromise vulnerable Windows systems.\n\nIts core operational features included:\n<ul>\n<li><strong>Mass-Mailing:</strong> Upon infecting a machine, Mytob harvested email addresses from the local address book, cached web pages, and documents. It then utilized its own built-in SMTP engine to mass-email copies of itself to those addresses, spoofing the \"From\" field to appear legitimate.</li>\n<li><strong>Vulnerability Exploitation:</strong> Many Mytob variants also propagated across local networks by exploiting unpatched Windows vulnerabilities (such as the LSASS vulnerability MS04-011) to execute arbitrary code on remote machines.</li>\n<li><strong>Backdoor/Botnet Capability:</strong> Infected machines were joined to a botnet. Mytob opened a backdoor (often on IRC ports or high TCP ports) allowing remote attackers to issue commands, download additional malware, or utilize the host for distributed denial-of-service (DDoS) attacks.</li>\n<li><strong>Security Disruption:</strong> To ensure survival, Mytob actively attempted to terminate processes associated with antivirus software and block access to security vendor websites by modifying the local Windows `HOSTS` file.</li>\n</ul>\n\n<h3>Historical Impact</h3>\nAt its peak, Mytob was responsible for a massive percentage of global malicious email traffic. The sheer volume of emails generated by the worm caused severe degradation of corporate mail servers and immense bandwidth consumption, resulting in millions of dollars in lost productivity.\n\n<h3>Modern Defense and Eradication</h3>\n<ul>\n<li><strong>Patch Management:</strong> Mytob heavily relied on exploiting legacy Windows vulnerabilities. Maintaining a rigorous, automated patch management schedule for all operating systems and software is critical to preventing network-based worm propagation.</li>\n<li><strong>Email Filtering:</strong> Implement robust, edge-based email security gateways to filter out executable attachments (`.exe`, `.scr`, `.pif`, `.zip` containing executables) before they reach user inboxes.</li>\n<li><strong>Network Segmentation:</strong> Ensure that internal networks are properly segmented to prevent the rapid lateral spread of worms utilizing SMB or RPC exploits.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Worm.Mytob",
    "Win32/Mytob",
    "Email-Worm.Win32.Mytob"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1566.001",
    "T1210",
    "T1105",
    "T1562.001",
    "T1498"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:27:47Z",
  "type": "Worm",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}