Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
BubbleBoy was a Visual Basic Script (VBScript) email worm first reported in November 1999. It exploited a vulnerability in the way certain versions of Microsoft Outlook, Outlook Express, Internet Explorer and Windows Scripting Host handled HTML email, allowing the worm to run when a message was rendered or opened—without a conventional executable attachment. “Virus” is the familiar historical name; technically, BubbleBoy was a self-propagating worm.
BubbleBoy in one minute
BubbleBoy was also known as VBS/BubbleBoy or the BubbleBoy worm. Its importance was not the severity of its known payload, which was comparatively limited, but its delivery method. It showed that active content inside an HTML message could be dangerous before a user deliberately launched an attachment.
The worm targeted legacy Windows 95, Windows 98 and Windows 2000-era installations with reported combinations of Internet Explorer 5-era components, Windows Scripting Host, and Outlook or Outlook Express. These are historical compatibility conditions, not requirements for current Windows systems.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Contemporary accounts describe BubbleBoy as an early example of a worm activating through rendered email on vulnerable Microsoft software. It was technically influential but was not as widespread as later outbreaks such as Melissa or LoveLetter.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How BubbleBoy infected a computer
- The message arrived. The worm used an HTML email with VBScript embedded in the message rather than relying on an obvious executable attachment.
- The client rendered the HTML. Vulnerable mail software used Internet Explorer-era rendering and ActiveX components to display the message.
- The script abused Scriptlet.Typelib. Microsoft’s MS99-032 bulletin describes the vulnerability: an ActiveX control that should not have been trusted as safe for scripting could be used to create or modify files locally.
- Files and startup settings changed. The worm created a file reported as
update.htaand added a startup mechanism so it could run again after a reboot. - Copies were sent automatically. Using Outlook automation, it mailed itself to addresses in the user’s local Outlook address books.
The key point is that “no attachment” did not mean “no exploit.” BubbleBoy still required a particular, vulnerable software stack and unsafe scripting behavior.
Could the Preview Pane trigger BubbleBoy?
There is no single answer for every Microsoft mail configuration. Contemporary reporting says BubbleBoy could activate when an HTML message was displayed in the Outlook Express Preview Pane. One account says Microsoft Outlook generally required the message to be opened, while other summaries use “opened” more broadly to include rendering or previewing.
The careful conclusion is that, on vulnerable systems, displaying or opening the message could be enough. The exact trigger depended on the client, its security-zone settings, the available Internet Explorer components and whether Windows Scripting Host and the vulnerable ActiveX control were present. It did not infect every Outlook or Outlook Express user who read email.
What did the email look like?
Historical reports identify the subject as BubbleBoy is back!. The body referred to “The BubbleBoy incident, pictures and sounds.” Those details help explain how the original specimen was recognized, but they are not a current detection signature. Modern attackers can copy old subjects or use entirely different wording.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What did BubbleBoy do after infection?
The known specimen made several visible or operational changes:
- It changed Windows registration information, including names associated with “Bubbleboy” and “Vandelay Industries.”
- It created or used
update.hta. - It established startup persistence.
- It sent copies of itself to Outlook address-book contacts.
Reports did not describe the original BubbleBoy payload as deleting files or formatting the hard drive. That does not make the technique harmless: the same ability to create and run files could have been paired with a far more destructive payload.
Why BubbleBoy mattered
Before this class of attack, users were often told that an email was safe if they did not execute an attached program. BubbleBoy challenged that assumption. A vulnerable client could process active HTML content as part of displaying the message, making cautious attachment-handling alone an incomplete defense.
Its legacy is the broader idea that content processing can be an attack surface. Later script-based worms, including Kak, used related HTML-email and Outlook Express techniques and spread more successfully. Kak was a distinct worm, not another name for BubbleBoy.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
BubbleBoy therefore had high historical significance but a comparatively limited known outbreak. A technical study describes it as not widespread in the wild, unlike the major email-worm epidemics that followed.
How was BubbleBoy stopped?
In 1999 and 2000, defenses included installing Microsoft’s patch for the Scriptlet.Typelib vulnerability, raising Internet Explorer security to High, restricting ActiveX and executable HTML content, avoiding vulnerable Outlook configurations, and using antivirus software with BubbleBoy detection. The relevant Microsoft bulletin was MS99-032.
Those menu paths and the patch itself are historical information, not a maintenance plan for a current computer. Today, the practical equivalents are to:
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute- Use a supported operating system and fully updated mail client.
- Retire or isolate obsolete Windows and Outlook/Outlook Express systems.
- Prevent untrusted scripts and active content from running automatically.
- Treat unexpected HTML messages, links and files as untrusted even when there is no executable attachment.
- If an old machine may be infected, disconnect it from networks before investigating or recovering data.
Can BubbleBoy infect a modern computer?
The original worm was designed for obsolete Windows and Microsoft mail components and is not a normal threat to a fully updated contemporary system. A current computer can still be compromised by other malicious HTML, scripts, attachments or software vulnerabilities, however. Modern email platforms usually sanitize or isolate active content more effectively, but “opening an email can never infect you” is too absolute: a vulnerability in any content-rendering software can turn passive processing into code execution.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
BubbleBoy versus a conventional computer virus
| Feature | BubbleBoy | Traditional file virus |
|---|---|---|
| Main propagation route | Email and address books | Infected files or removable media |
| Typical user action | Rendering or opening vulnerable HTML email | Opening or executing an infected file |
| Technology | VBScript, HTML and ActiveX | Varies by virus |
| Replication style | Worm-like automatic emailing | Infection of other files or media |
| Historical significance | Showed that email rendering could be an attack surface | Represented conventional file infection |
Frequently asked questions
Was BubbleBoy the first email virus?
It was widely described as an early, and in some accounts the first known, worm to activate through rendered HTML email on vulnerable Microsoft systems. “First” depends on how the category is defined, so an unqualified claim about every email-borne virus would be misleading.
Did BubbleBoy require an attachment?
No conventional executable attachment was required. The VBScript was embedded in HTML email, but infection still depended on vulnerable rendering software and security settings.
Was BubbleBoy destructive?
The reported specimen mainly changed registration data, established startup persistence and mailed copies to contacts. It was not reported to erase files or format disks, although the exploit mechanism could have supported more damaging code.
Is “BubbleBoy virus” technically correct?
It is the common historical name. “Email worm” or “script-based worm” is more precise because BubbleBoy replicated automatically through address books rather than primarily infecting executable files.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Frequently Asked Questions
What was the BubbleBoy email subject?
Contemporary reports list BubbleBoy is back!, but that is a historical indicator, not a current detection rule.
How was BubbleBoy related to Kak?
BubbleBoy demonstrated HTML-email scripting and rendering-based propagation; the later Kak worm used related techniques and became more prevalent. They were separate worms.
The Bottom Line
BubbleBoy is mainly a lesson in software security history: a mild 1999 payload made a serious point about how vulnerable email clients could execute active content simply while displaying a message. The original worm targets obsolete software, but the principle—keep software patched and prevent untrusted content from running automatically—still applies.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

