CACrown ArchivesThe cinema collection
Menu
Research dossier · General Reference

Storm Worm

backdoor Trojan horse found in Windows

Cross-disciplinary reference desk with index cards, atlas, dictionary and catalogue
General referenceInterpretive dossier study · Crown Archives visual atlas
Record originEnglish Wikipedia
Text licenseCC BY-SA 4.0
Source revisionJun 7, 2026
Entity authorityQ3068129
Source-derived summary

The Storm Worm (dubbed so by the Finnish company F-Secure) is a phishing backdoor Trojan horse that affects computers using Microsoft operating systems, discovered on January 17, 2007. The worm is also known as:

Small.dam or Trojan-Downloader.Win32.Small.dam (F-Secure)

CME-711 (MITRE)

W32/Nuwar@MM and Downloader-BAI (specific variant) (McAfee)

Troj/Dorf and Mal/Dorf (Sophos)

Trojan.DL.Tibs.Gen!Pac13

Trojan.Downloader-647

Trojan.Peacomm (Symantec)

TROJ_SMALL.EDW (Trend Micro)

Win32/Nuwar (ESET)

Win32/Nuwar.N@MM!CME-711 (Windows Live OneCare)

W32/Zhelatin (F-Secure and Kaspersky)

Trojan.Peed, Trojan.Tibs (BitDefender)

The Storm Worm began attacking thousands of (mostly private) computers in Europe and the United States on Friday, January 19, 2007, using an e-mail message with a subject line about a recent weather disaster, "230 dead as storm batters Europe". During the weekend there were six subsequent waves of the attack. As of January 22, 2007, the Storm Worm accounted for 8% of all malware infections globally.

There is evidence, according to PCWorld, that the Storm Worm was of Russian origin, possibly traceable to the Russian Business Network.

History

Originally propagated in messages about Cyclone Kyrill, the Storm Worm has also been seen in emails with the following subjects:

230 dead as storm batters Europe. [The worm was dubbed "Storm" because of this message subject.]

A killer at 11, he's free at 21 and kill again!

U.S. Secretary of State Condoleezza Rice has kicked German Chancellor Angela Merkel

British Muslims Genocide

Naked teens attack home director.

Re: Your text

Radical Muslim drinking enemies' blood.

Chinese/Russian missile shot down Russian/Chinese satellite/aircraft

Saddam Hussein safe and sound!

Editorial summary

“Storm Worm” enters the record as backdoor Trojan horse found in Windows. Crown Archives preserves that source wording while asking what Storm, Worm and backdoor can confirm, complicate or overturn.

Editorial reviewA practical starting point whose main value is the path it opens into stronger specialist and primary sources. The current lead gives the account dated anchors—2007—that can be checked directly. The selected authority fields contribute no independent date. Its strongest next move is a source search built around Storm, Worm and backdoor.
Editorial analysis

Why this record matters

“Storm Worm” is worth following because a concise public description often conceals a longer documentary argument. Here, Storm, Worm and backdoor provides the most credible route into that argument.

Evidence profile

The citation trail is more important than the brevity of the summary: it shows where individual claims can be examined in context. The source revision retrieved here is dated Jun 7, 2026. The linked authority identifier is Q3068129. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2007.

Critical limits

The absence of detail may reflect summary conventions rather than a lack of surviving documentation. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.

How to read it

Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.

Best used for
  • Subject orientation
  • Search vocabulary
  • Locating named sources
Verify next

The closest primary source, responsible institution and strongest cited specialist reference.

Three-step research path

  1. Establish the record: confirm the title “Storm Worm”, its source revision and the description used here.
  2. Expand the search: follow Storm Worm primary sources, Storm Worm archive and Storm research across catalogues and specialist indexes.
  3. Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.

Questions for further research

  1. Which source most directly establishes the central claim about “Storm Worm”?
  2. Which cited source is closest to the event, object or claim?
  3. Which institution is responsible for the underlying evidence?
Subject index

Search terms from this dossier

Source & attribution

This entry incorporates text from Storm Worm” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.