Code Red Turns 25: The Worm That Still Has Things to Teach Us

A worm that spread across the internet in 2001 exposed a security blind spot that organisations keep rediscovering. Today, AI tools are the new version of the same problem.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style 16:9 image of a dark server room with faint green code reflections across black rackmount hardware, a single keyboard resting on
Share

Key points

  • The Code Red worm, a self-spreading malicious program, was co-discovered by Marc Maiffret and Ryan Permeh on a Friday night in July 2001 after two customer complaints.
  • Code Red exploited a flaw in Microsoft Internet Information Services (IIS), the software that runs websites on Windows servers, which was switched on by default at millions of organisations.
  • The worm was among the first to spread across the open internet rather than through email, hitting organisations worldwide before most knew a patch existed.
  • BeyondTrust CTO Marc Maiffret, speaking in a discussion first covered by Dark Reading, says the AI adoption rush today mirrors the same visibility failures that made Code Red so damaging.
  • Security experts say the core lesson from 2001 still applies: you cannot protect systems you do not know you are running.

Twenty-five years ago this summer, two security researchers were unwinding on a Friday evening when their inboxes filled up with worried messages. Customers were reporting that their web servers, the computers that host websites, were behaving strangely. Neither customer could explain exactly what was wrong.

Marc Maiffret and Ryan Permeh started digging through packet captures, which are recordings of network traffic, like call logs for computers. What they found was not a standard break-in. Something was moving through machines on its own, copying itself from server to server without any human pushing it.

That was Code Red.

The worm, named partly after a Mountain Dew soda, targeted a flaw in Microsoft Internet Information Services (IIS), Windows software that powers web servers. IIS came switched on by default. Millions of organisations were running it without knowing. Many had never applied the available patch, a software fix Microsoft had already released.

Code Red defaced websites with the message "Hacked by Chinese" and carried a built-in ability to flood targets with junk traffic, a technique called a distributed denial-of-service (DDoS) attack, designed to knock websites offline. It spread fast enough to hit organisations across the planet before most IT teams realised a worm existed.

How does a 2001 worm connect to AI tools in 2024?

The connection is the blind spot, not the technology. Code Red succeeded because organisations were running software they had forgotten about, had never secured, and had no easy way to find. Maiffret argues the same pattern is playing out now with artificial intelligence.

Companies are deploying AI tools, AI-powered assistants, and automated AI workflows at speed, often without a clear picture of what is actually running inside their own networks. Security teams call this "shadow AI", meaning AI tools adopted by staff or departments without formal approval or oversight. If you do not know a tool exists inside your organisation, you cannot check whether it is safe.

The parallel is precise. In 2001 the overlooked service was a web server. Today it might be a third-party AI chatbot connected to company data, or an automated workflow that nobody in the security team signed off on.

Maiffret's advice is to start from first principles: step one in security is knowing what you have. That was true in 2001. It is true now.

For ordinary employees, the practical takeaway is simple. If you are using an AI tool at work that your IT or security team has not approved, flag it. Shadow tools create blind spots, and blind spots are where incidents start.

© 2026 Threat Vectr