ROOT / WORLD PROJECTS / COMPUTER VIRUSES // DECODED CYBER · THREAT ARCHIVE
Computer Viruses // Decoded

Code that
fights back.

Fifty years of malicious software — from a harmless 1971 experiment that hopped between ARPANET machines, to worms that crippled the internet in ten minutes, to nation-state weapons that physically destroyed centrifuges. This is the full lineage: what each one was, how it spread, and the damage it left behind.

1971
First self-replicating program (Creeper)
$10B+
Damage from ILOVEYOU (2000)
200k+
Machines hit by WannaCry · 150 countries
$10B
NotPetya — costliest cyberattack ever
// The five eras of malware

How the threat evolved.

Malware tracks the machines it targets. As computing moved from floppy disks to always-on networks to the cloud and industrial control systems, the attackers followed — and the motive shifted from mischief to money to war.

1971–1995 · Experiments & floppy-borne infectors. The first "viruses" spread on physical disks and were often academic curiosities or pranks. Boot-sector and file infectors like Brain and Michelangelo defined the genre; the word "virus" entered the lexicon.

1999–2004 · The macro & email worm epidemic. Office macros and Outlook address books turned every inbox into a vector. Melissa, ILOVEYOU, Code Red, Nimda, SQL Slammer, Blaster and Sasser spread faster than humans could patch, taking down airlines, banks and news sites.

2007–2010 · Botnets & organized crime. Conficker built a botnet of millions; malware became infrastructure for spam, fraud and rentable attack capacity. Domain-generation algorithms and peer-to-peer command-and-control made takedowns hard.

2010–2017 · Cyberweapons & the nation-state era. Stuxnet proved code could break machines. Wipers (Shamoon, BlackEnergy) and supply-chain attacks (NotPetya, SolarWinds) turned malware into a tool of statecraft and sabotage.

2013–now · Ransomware-as-a-Service. Encryption plus cryptocurrency made extortion scalable. CryptoLocker, WannaCry, Ryuk, REvil, LockBit and BlackCat professionalized the ransom economy with affiliates, leak sites and double-extortion.

// 1971–1999 · classic viruses

Early boot & file infectors

The pioneers — mostly small, mostly DOS-era, and mostly spread by hand on floppy disks.

VirusYearTargetWhat it did
Creeper1971TENEX · ARPANETFirst experimental self-replicating program. Printed "I'm the creeper, catch me if you can!" Harmless; inspired "Reaper," the first antivirus.
Elk Cloner1982Apple IIFirst virus "in the wild." Spread via floppy; displayed a poem every 50th boot.
Brain1986MS-DOS (360KB floppy)First PC boot-sector virus. Altered the volume label and trapped disk reads; written by two brothers in Pakistan.
Michelangelo1991DOS boot sectorTime-bomb that overwrote raw disk sectors every March 6 (the artist's birthday). Triggered a global media panic.
CIH / Chernobyl1998Windows 95/98Overwrote the BIOS flash and partition tables — one of the first to physically brick hardware. Estimated $1B damage across 60M PCs.
Melissa1999MS Word · OutlookMass-mailing macro virus; emailed infected documents to the first 50 Outlook contacts, overwhelming mail servers worldwide.
// 2000–2008 · network worms

The internet outbreaks

Self-propagating code that needed no human to click — spreading over the network itself, sometimes infecting the world in minutes.

WormYearVectorImpact
ILOVEYOU (Love Bug)2000VBScript · OutlookTens of millions of PCs in hours via a "love letter" attachment. Overwrote files. Est. $10B+ damage; one of the most destructive ever.
Code Red2001Microsoft IISBuffer-overflow worm; defaced sites ("Hacked by Chinese!") and launched DDoS at the White House. 359,000 hosts in 14 hours.
Nimda2001Web · email · sharesFive infection vectors at once; became the internet's most widespread worm within 22 minutes of release.
SQL Slammer2003MS SQL Server 2000376-byte worm; doubled every 8.5 seconds and saturated global bandwidth in under 10 minutes, downing ATMs and airline systems.
Blaster (MSBlast)2003Windows RPC/DCOMForced reboot loops and aimed a DDoS at windowsupdate.com. Carried the taunt "billy gates why do you make this possible?"
Sasser2004Windows LSASSNo user action needed. Grounded flights, halted trains and shut down bank branches. Written by a 17-year-old.
Conficker2008Windows Server serviceBuilt a botnet across up to 15M machines using domain-generation algorithms; still detected in the wild years later. Spawned a global response cabal.
// 2010–2020 · cyberweapons & APTs

When code became a weapon

Nation-state operations built to spy, sabotage and destroy — the point where malware crossed from crime into warfare.

OperationYearTargetSignificance
Stuxnet2010Iranian SCADA / PLCsFirst cyber-weapon to cause physical destruction — spun 1,000 uranium centrifuges to failure while faking normal readings. Used four zero-days.
Shamoon2012Saudi AramcoWiper that overwrote the master boot record and erased 30,000 workstations, crippling the world's largest oil company for weeks.
BlackEnergy2015Ukraine power gridFirst malware to cause a confirmed power blackout — 230,000 people lost electricity in mid-winter.
NotPetya2017Global supply chainFake ransomware built purely to destroy; spread via a Ukrainian tax-software update. $10B in damage worldwide — the costliest cyberattack in history.
SolarWinds (SUNBURST)2020Software supply chainBackdoor slipped into Orion updates; compromised 18,000 organizations including US federal agencies. The defining supply-chain espionage case.
// 2013–now · ransomware

The extortion economy

Encrypt the victim's files, demand cryptocurrency, and — increasingly — steal the data first so paying is the only way to stop a public leak.

FamilyFirst seenVectorSignature move
CryptoLocker2013Trojan · emailPioneered modern RSA/AES asymmetric encryption with Bitcoin ransom. Grossed millions before its botnet (Gameover Zeus) was taken down.
WannaCry2017EternalBlue (SMBv1)Worm-ransomware hybrid; 200,000+ machines in 150 countries in a day. Crippled the UK's NHS. Stopped by a "kill-switch" domain.
Ryuk2018TrickBot / EmotetHuman-operated, big-game hunting of hospitals and city governments; multi-million-dollar demands.
REvil (Sodinokibi)2019RaaS · MSPsDouble-extortion pioneer; the Kaseya supply-chain hit encrypted 1,500 businesses at once. $70M demand.
LockBit2019Network access · RaaSThe most prolific RaaS platform of its era — automated, self-spreading, with the fastest known encryption speeds. Disrupted by law enforcement in 2024.
BlackCat (ALPHV)2021Rust payloadFirst major cross-platform Rust ransomware; hit Windows, Linux and VMware ESXi. Behind the Change Healthcare breach.
// deep dive

Five that changed everything.

◊ 1988 · the first internet worm

The Morris Worm

Graduate student Robert Morris released a worm meant to gauge the size of the internet. A flaw in its spread logic re-infected machines relentlessly, crashing 6,000 systems (roughly 10% of the internet). It led to the first felony conviction under the US Computer Fraud and Abuse Act and the creation of the first CERT — the birth of coordinated cyber-defense.

◊ 2000 · the love that broke the inbox

ILOVEYOU

A Visual Basic script disguised as a love letter overwrote images and documents, then mailed itself to every Outlook contact. Within ten days it hit an estimated 45 million machines — the Pentagon, CIA and UK Parliament pulled mail offline. Because the Philippines had no anti-hacking law, its author was never charged; the case drove new cybercrime legislation worldwide.

◊ 2010 · the digital bomb

Stuxnet

A 500KB worm of unprecedented sophistication targeted the Siemens PLCs controlling Iran's Natanz enrichment plant. It quietly varied centrifuge speeds to destroy them while replaying normal telemetry to operators. Widely attributed to a US–Israeli operation ("Olympic Games"), it proved software could cross into the physical world — and opened the era of cyber-physical warfare.

◊ 2017 · the $10B fake ransom

NotPetya

Masquerading as ransomware but designed only to destroy, NotPetya spread from a hijacked Ukrainian accounting-software update using the leaked EternalBlue exploit. It leapt across global networks — Maersk, Merck, FedEx and Mondelez each lost hundreds of millions; total damage topped $10 billion, making it the most financially destructive cyberattack ever recorded.

// landmark incidents

Breaches that reshaped security

YearIncidentWhy it mattered
1988Morris WormFirst major internet worm; first CFAA conviction; birth of CERT.
2000Mafiaboy DDoSA teenager took down Yahoo, eBay, CNN and Amazon — exposed how fragile the early web was.
2013Target breach40M cards stolen via an HVAC vendor's credentials — the wake-up call for supply-chain and vendor risk.
2014Sony PicturesDestructive wiper + mass leak of internal data; attributed to North Korea over a film release.
2015OPM breach21.5M US security-clearance records exfiltrated — one of the most damaging espionage hauls in history.
2017EquifaxAn unpatched Apache Struts flaw exposed 147M consumers' financial data. Defined the cost of poor patching.
2021Colonial PipelineOne leaked VPN password → a DarkSide ransomware hit shut the largest US fuel pipeline; fuel panic across the East Coast.
// research · threat intelligence

Where the pros track it

The authoritative, public repositories that catalog adversary techniques, vulnerabilities and live malware samples.

MITRE ATT&CK

The global knowledge base of adversary tactics and techniques — the shared language of cyber-defense.

NIST NVD

The US government's National Vulnerability Database — every standardized CVE with severity scoring.

MalwareBazaar (abuse.ch)

Community repository of live malware sample hashes, signatures and YARA rules.

CISA KEV

The Known Exploited Vulnerabilities catalog — flaws confirmed to be actively exploited in the wild.

◊ Sources: MITRE ATT&CK (attack.mitre.org) · NIST NVD (nvd.nist.gov) · abuse.ch MalwareBazaar · CISA KEV · CERT/CC historical incident records. Figures are widely-cited public estimates; damage totals are approximate.