A worm is a type of malware that copies itself and spreads from one computer to another on its own, without needing to attach to files or wait for users to run it.
How worms spread
Unlike a virus, which infects files and depends on users opening them, a worm is a standalone program that actively looks for new victims. Typical spreading methods include:
- exploiting network remote code execution vulnerabilities in services such as SMB or RDP;
- guessing weak passwords on network shares, SSH and IoT devices;
- sending copies of itself by email, messengers or removable USB drives.
Because every infected machine starts scanning for others, worms can spread exponentially and cover the world within hours.
Famous worms
- Morris worm (1988) – one of the first internet worms, which disabled thousands of computers.
- ILOVEYOU (2000) – an email worm that reached tens of millions of PCs.
- Conficker (2008) – infected millions of Windows systems and built a huge botnet.
- WannaCry (2017) – ransomware with a worm module based on the EternalBlue exploit, which hit hospitals, factories and companies in about 150 countries.
- NotPetya (2017) – a destructive worm disguised as ransomware.
Why worms matter
Any “wormable” vulnerability – exploitable over the network without authentication or user interaction – is treated as critical, because it can turn into a global outbreak of malware. Worm components are also used by botnets and cryptominers.
How to defend
- Patch network services quickly, especially wormable flaws.
- Disable legacy protocols such as SMBv1 and avoid exposing SMB and RDP to the internet.
- Segment networks so that one infection cannot reach everything.
- Use strong unique passwords on servers and IoT devices.