My favourite: https://en.wikipedia.org/wiki/SQL_Slammer - 376 bytes of malware, spread via spraying UDP packets at random IP addresses, infected basically every vulnerable system on the entire internet within 10 minutes.
A sibling has already linked it, but extra context: Robert Tappen Morris (aka ‘rtm’) is a legend, his dad is a Bell Labs legend, and along with Trevor he’s kind of the “silent partner” in the Viaweb -> YC -> $$$$$ miracle.
Guy’s a boss.
I think they talk about worms that spread by infecting other devices in the local network using RCEs in net-services like rdp/smb/..
That or maybe drive-by downloads / java/activeX code execution, which have become more rare