Netskope Threat Labs

Bagle

ATP Sandbox Adv. HeuristicsAV

Bagle is a mass mailing worm that spread rapidly through email attachments in the early 2000s and opened a backdoor on infected Windows systems. It harvests email addresses from infected machines to propagate further and can download additional malware payloads from remote servers. The family infected enormous numbers of systems during its peak, and its code circulated underground for years, influencing later worm families.

First seen
April 2022
Last seen
October 2026
Alert Name
Archive-ZIP.Worm.Bagle
Dump:Generic.Bagle.2.217FBEF4
Dump:Generic.Bagle.4.DEDAB463
Dump:Win32.Bagle.AM@mm
MemScan:Win32.Bagle.123
MemScan:Win32.Bagle.AM@mm
Trojan.Bagle.BK
Trojan.Bagle.EC
Trojan.Downloader.Bagle.AQ
Win32.Bagle.10.Gen@mm