Critical severity Malware

Worm

Self-propagating malware that spreads without any user action or host program.

Overview

A worm carries its own transport: it scans for open shares, vulnerable services or mail addresses and copies itself onward.\nBecause no human is in the loop, growth is exponential, which is why a single infected host can exhaust a network within hours.\nSegmentation and rapid patching of the exploited service are the practical brakes.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Sudden surge in internal scan traffic
  • New copies of the same file across many hosts
  • Outbound connection attempts to many random ports

Controls that stop it

  • Segment the Network and Restrict Egress

    Do not let every host talk to every other host or to the whole internet. Segment by role, deny inbound administration from user networks, and filter outbound traffic so only the destinations a workload genuinely needs are reachable. Egress control is what stops an SSRF or an implant from reaching cloud metadata and command infrastructure.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used