Fifty years of malicious software — from a harmless 1971 experiment that hopped between ARPANET machines, to worms that crippled the internet in ten minutes, to nation-state weapons that physically destroyed centrifuges. This is the full lineage: what each one was, how it spread, and the damage it left behind.
Malware tracks the machines it targets. As computing moved from floppy disks to always-on networks to the cloud and industrial control systems, the attackers followed — and the motive shifted from mischief to money to war.
1971–1995 · Experiments & floppy-borne infectors. The first "viruses" spread on physical disks and were often academic curiosities or pranks. Boot-sector and file infectors like Brain and Michelangelo defined the genre; the word "virus" entered the lexicon.
1999–2004 · The macro & email worm epidemic. Office macros and Outlook address books turned every inbox into a vector. Melissa, ILOVEYOU, Code Red, Nimda, SQL Slammer, Blaster and Sasser spread faster than humans could patch, taking down airlines, banks and news sites.
2007–2010 · Botnets & organized crime. Conficker built a botnet of millions; malware became infrastructure for spam, fraud and rentable attack capacity. Domain-generation algorithms and peer-to-peer command-and-control made takedowns hard.
2010–2017 · Cyberweapons & the nation-state era. Stuxnet proved code could break machines. Wipers (Shamoon, BlackEnergy) and supply-chain attacks (NotPetya, SolarWinds) turned malware into a tool of statecraft and sabotage.
2013–now · Ransomware-as-a-Service. Encryption plus cryptocurrency made extortion scalable. CryptoLocker, WannaCry, Ryuk, REvil, LockBit and BlackCat professionalized the ransom economy with affiliates, leak sites and double-extortion.
The pioneers — mostly small, mostly DOS-era, and mostly spread by hand on floppy disks.
| Virus | Year | Target | What it did |
|---|---|---|---|
| Creeper | 1971 | TENEX · ARPANET | First experimental self-replicating program. Printed "I'm the creeper, catch me if you can!" Harmless; inspired "Reaper," the first antivirus. |
| Elk Cloner | 1982 | Apple II | First virus "in the wild." Spread via floppy; displayed a poem every 50th boot. |
| Brain | 1986 | MS-DOS (360KB floppy) | First PC boot-sector virus. Altered the volume label and trapped disk reads; written by two brothers in Pakistan. |
| Michelangelo | 1991 | DOS boot sector | Time-bomb that overwrote raw disk sectors every March 6 (the artist's birthday). Triggered a global media panic. |
| CIH / Chernobyl | 1998 | Windows 95/98 | Overwrote the BIOS flash and partition tables — one of the first to physically brick hardware. Estimated $1B damage across 60M PCs. |
| Melissa | 1999 | MS Word · Outlook | Mass-mailing macro virus; emailed infected documents to the first 50 Outlook contacts, overwhelming mail servers worldwide. |
Self-propagating code that needed no human to click — spreading over the network itself, sometimes infecting the world in minutes.
| Worm | Year | Vector | Impact |
|---|---|---|---|
| ILOVEYOU (Love Bug) | 2000 | VBScript · Outlook | Tens of millions of PCs in hours via a "love letter" attachment. Overwrote files. Est. $10B+ damage; one of the most destructive ever. |
| Code Red | 2001 | Microsoft IIS | Buffer-overflow worm; defaced sites ("Hacked by Chinese!") and launched DDoS at the White House. 359,000 hosts in 14 hours. |
| Nimda | 2001 | Web · email · shares | Five infection vectors at once; became the internet's most widespread worm within 22 minutes of release. |
| SQL Slammer | 2003 | MS SQL Server 2000 | 376-byte worm; doubled every 8.5 seconds and saturated global bandwidth in under 10 minutes, downing ATMs and airline systems. |
| Blaster (MSBlast) | 2003 | Windows RPC/DCOM | Forced reboot loops and aimed a DDoS at windowsupdate.com. Carried the taunt "billy gates why do you make this possible?" |
| Sasser | 2004 | Windows LSASS | No user action needed. Grounded flights, halted trains and shut down bank branches. Written by a 17-year-old. |
| Conficker | 2008 | Windows Server service | Built a botnet across up to 15M machines using domain-generation algorithms; still detected in the wild years later. Spawned a global response cabal. |
Nation-state operations built to spy, sabotage and destroy — the point where malware crossed from crime into warfare.
| Operation | Year | Target | Significance |
|---|---|---|---|
| Stuxnet | 2010 | Iranian SCADA / PLCs | First cyber-weapon to cause physical destruction — spun 1,000 uranium centrifuges to failure while faking normal readings. Used four zero-days. |
| Shamoon | 2012 | Saudi Aramco | Wiper that overwrote the master boot record and erased 30,000 workstations, crippling the world's largest oil company for weeks. |
| BlackEnergy | 2015 | Ukraine power grid | First malware to cause a confirmed power blackout — 230,000 people lost electricity in mid-winter. |
| NotPetya | 2017 | Global supply chain | Fake ransomware built purely to destroy; spread via a Ukrainian tax-software update. $10B in damage worldwide — the costliest cyberattack in history. |
| SolarWinds (SUNBURST) | 2020 | Software supply chain | Backdoor slipped into Orion updates; compromised 18,000 organizations including US federal agencies. The defining supply-chain espionage case. |
Encrypt the victim's files, demand cryptocurrency, and — increasingly — steal the data first so paying is the only way to stop a public leak.
| Family | First seen | Vector | Signature move |
|---|---|---|---|
| CryptoLocker | 2013 | Trojan · email | Pioneered modern RSA/AES asymmetric encryption with Bitcoin ransom. Grossed millions before its botnet (Gameover Zeus) was taken down. |
| WannaCry | 2017 | EternalBlue (SMBv1) | Worm-ransomware hybrid; 200,000+ machines in 150 countries in a day. Crippled the UK's NHS. Stopped by a "kill-switch" domain. |
| Ryuk | 2018 | TrickBot / Emotet | Human-operated, big-game hunting of hospitals and city governments; multi-million-dollar demands. |
| REvil (Sodinokibi) | 2019 | RaaS · MSPs | Double-extortion pioneer; the Kaseya supply-chain hit encrypted 1,500 businesses at once. $70M demand. |
| LockBit | 2019 | Network access · RaaS | The most prolific RaaS platform of its era — automated, self-spreading, with the fastest known encryption speeds. Disrupted by law enforcement in 2024. |
| BlackCat (ALPHV) | 2021 | Rust payload | First major cross-platform Rust ransomware; hit Windows, Linux and VMware ESXi. Behind the Change Healthcare breach. |
Graduate student Robert Morris released a worm meant to gauge the size of the internet. A flaw in its spread logic re-infected machines relentlessly, crashing 6,000 systems (roughly 10% of the internet). It led to the first felony conviction under the US Computer Fraud and Abuse Act and the creation of the first CERT — the birth of coordinated cyber-defense.
A Visual Basic script disguised as a love letter overwrote images and documents, then mailed itself to every Outlook contact. Within ten days it hit an estimated 45 million machines — the Pentagon, CIA and UK Parliament pulled mail offline. Because the Philippines had no anti-hacking law, its author was never charged; the case drove new cybercrime legislation worldwide.
A 500KB worm of unprecedented sophistication targeted the Siemens PLCs controlling Iran's Natanz enrichment plant. It quietly varied centrifuge speeds to destroy them while replaying normal telemetry to operators. Widely attributed to a US–Israeli operation ("Olympic Games"), it proved software could cross into the physical world — and opened the era of cyber-physical warfare.
Masquerading as ransomware but designed only to destroy, NotPetya spread from a hijacked Ukrainian accounting-software update using the leaked EternalBlue exploit. It leapt across global networks — Maersk, Merck, FedEx and Mondelez each lost hundreds of millions; total damage topped $10 billion, making it the most financially destructive cyberattack ever recorded.
| Year | Incident | Why it mattered |
|---|---|---|
| 1988 | Morris Worm | First major internet worm; first CFAA conviction; birth of CERT. |
| 2000 | Mafiaboy DDoS | A teenager took down Yahoo, eBay, CNN and Amazon — exposed how fragile the early web was. |
| 2013 | Target breach | 40M cards stolen via an HVAC vendor's credentials — the wake-up call for supply-chain and vendor risk. |
| 2014 | Sony Pictures | Destructive wiper + mass leak of internal data; attributed to North Korea over a film release. |
| 2015 | OPM breach | 21.5M US security-clearance records exfiltrated — one of the most damaging espionage hauls in history. |
| 2017 | Equifax | An unpatched Apache Struts flaw exposed 147M consumers' financial data. Defined the cost of poor patching. |
| 2021 | Colonial Pipeline | One leaked VPN password → a DarkSide ransomware hit shut the largest US fuel pipeline; fuel panic across the East Coast. |
The authoritative, public repositories that catalog adversary techniques, vulnerabilities and live malware samples.
The global knowledge base of adversary tactics and techniques — the shared language of cyber-defense.
The US government's National Vulnerability Database — every standardized CVE with severity scoring.
Community repository of live malware sample hashes, signatures and YARA rules.
The Known Exploited Vulnerabilities catalog — flaws confirmed to be actively exploited in the wild.
◊ Sources: MITRE ATT&CK (attack.mitre.org) · NIST NVD (nvd.nist.gov) · abuse.ch MalwareBazaar · CISA KEV · CERT/CC historical incident records. Figures are widely-cited public estimates; damage totals are approximate.