Kelvir

Category: trojan · Aliases: Worm.Win32.Kelvir, IM-Worm.Kelvir, W32/Kelvir · Sample count (EMBER 2018): 1 · Enrichment: insufficient_information · Updated: 2026-07-01T16:48:23Z
Category: TrojanActor: Unknown / CybercriminalIndustry: Global / OpportunisticMotivation: Opportunistic

Overview

Executive Summary

Kelvir is a widespread and aggressive family of Worms that primarily propagate by exploiting instant messaging networks, most notably the legacy MSN Messenger (Windows Live Messenger) platform. Emerging in the mid-2000s, Kelvir rapidly infected millions of computers globally. By hijacking the victim's IM client and leveraging social engineering, Kelvir rapidly spreads across contact lists, degrading network performance and often dropping secondary backdoor trojans.

Propagation and Execution Lifecycle

Kelvir relies on aggressive, largely automated propagation techniques utilizing social engineering:

Threat Assessment

While the specific MSN Messenger platform is obsolete, the propagation mechanics of Kelvir (abusing trusted communication channels) remain highly relevant today (e.g., spreading via Slack, Teams, or WhatsApp). An infection represents a significant security incident, as the rapid propagation can overwhelm network bandwidth and the secondary payloads compromise endpoint integrity.

Eradication and Incident Response

Known aliases

Threat reports may refer to this family under multiple names:

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1566.002 T1562.001 T1059

Tactical Mitigations

Based on the techniques used by this family, consider the following defensive strategies:

Generated Detections (Boilerplate)

These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.

YARA Rule

rule MALWARE_WIN_KELVIR {
    meta:
        description = "Detects Kelvir (trojan)"
        author = "SystemHelpdesk Boilerplate Generator"
        date = "2026-07-06"
    strings:
        $s1 = "kelvir" ascii wide nocase
        $s2 = "worm.win32.kelvir" ascii wide nocase
        $s3 = "im-worm.kelvir" ascii wide nocase
        $s4 = "w32/kelvir" ascii wide nocase
    condition:
        uint16(0) == 0x5a4d and any of them
}

Sigma Rule

title: Suspicious Kelvir Activity
id: e09c40ea41b7c31c8d53d479eae32d34
status: experimental
description: Detects generic indicators of the kelvir malware family.
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith:
            - '\cmd.exe'
            - '\powershell.exe'
        CommandLine|contains:
            - "*kelvir*"
            - "*worm.win32.kelvir*"
            - "*im-worm.kelvir*"
            - "*w32/kelvir*"
    condition: selection
level: medium

References & External Analysis

Frequently Asked Questions

How do I remove the Kelvir Trojan from Windows?

Manual removal of Kelvir is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.

Is Kelvir a virus or a Trojan?

Kelvir is classified as a Trojan. Unlike traditional viruses that infect files, modern malware like Kelvir typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.

What are the main symptoms of a Kelvir infection?

Symptoms of Kelvir can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.

Related Families (Category: trojan)

Explore other malware families in the same category:

Protect Your Network Against Trojans

Want to prevent Kelvir and similar threats from compromising your organization? Read our comprehensive defensive guide: Banking Trojan Protection.

Need help with an active incident? Published by the SystemHelpdesk team.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/kelvir.json

Ecosystem & Interactive Environments

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.