The Virus Decade
Mass malware became a public event. Melissa, ILOVEYOU, Code Red, Nimda, Slammer and Conficker spread fast enough to make the evening news, and taught a generation of users what an attachment could do.
Part of Cybersecurity
24 moments in this segment.
- — Source code of the Melissa macro virus. An excerpt of the Word macro source of Melissa, released 26 March 1999, which mailed itself to the first fifty entries in each victim's Outlook address book. It forced Microsoft and others to shut down mail gateways entirely and is the first mass-mailing worm with real economic cost. Released CC0. The subject dates from 1999; the photograph itself is later.
- — Arrest in the Melissa virus investigation. Associated Press footage from 3 April 1999 reporting the arrest and charging of a man over the Melissa email virus, tracked down with help from America Online technicians and a computer task force. It documents an early example of industry and law enforcement working a malware case together.
- — Court appearance of the man accused of writing Melissa. Associated Press footage from 9 April 1999 of David Smith, aged thirty, appearing in court charged with interrupting public communications, conspiracy and theft of a computer service in connection with the Melissa virus. Among the earliest courtroom footage of a malware prosecution.
- — The ILOVEYOU / Love Letter worm. The Love Letter worm, sent from Manila on 4 May 2000 as an attachment named LOVE-LETTER-FOR-YOU.TXT.vbs. It overwrote files and re-mailed itself to every Outlook contact, hitting tens of millions of machines within days; the Philippines had no law to charge the author under. It is the moment social engineering beat technical controls at global scale. The subject dates from 2000; the photograph itself is later.
- — Brazilian TV news report on the ILOVEYOU virus. A Jornal da Globo report from 2000 covering the ILOVEYOU mail worm as it spread through Windows machines worldwide. Period Brazilian broadcast coverage of the outbreak.
- — German TV warning about the ILOVEYOU worm. A tagesschau bulletin broadcast on 4 May 2000, the day the ILOVEYOU worm spread explosively by email across Europe. Period German broadcast coverage, re-posted twenty years later.
- — Investigation into the origin of the Code Red worm in China. Associated Press footage from 3 September 2001 from a university computer department in China, filmed as investigators looked into where the Code Red worm was written. Early evidence of how transnational a worm investigation had already become.
- — Code Red cleanup tool on The Screen Savers. Bob Lee appears on TechTV's The Screen Savers to discuss a program he wrote to stop the spread of the Code Red worm. The segment captures the improvised, self-help response of the technical community during the 2001 outbreak, when patching lagged far behind infection.
- — CNN interview on the Nimda worm. A CNN Financial News interview recorded on 18 September 2001, a day after the Nimda worm began spreading through Windows systems and web servers. Contemporaneous broadcast footage of the response to a mass-malware outbreak, uploaded years later by the interviewee.
- — CNN interview on internet security during the Code Red outbreak. A CNN interview with Aled Miles on internet security in the middle of the Code Red worm outbreak. Period coverage of how the security industry addressed a fast-spreading worm.
- — FBI press conference on the Code Red worm. Associated Press footage from a press conference on 30 July 2001 including Ron Dick, head of the FBI's National Infrastructure Protection Center, describing Code Red as the latest in a series of worms used to launch distributed attacks. A rare on-camera record of the federal response as the outbreak was under way.
- — Mikko Hypponen. of F-Secure, one of the few researchers who worked through the whole worm era and is still a public voice in the ransomware one. F-Secure's analyses of Melissa, Slammer, Sasser and later Stuxnet ran in real time. Released CC0 by Hypponen himself.
- — Spread of the Conficker worm. A contemporaneous map of Conficker's spread, drawn in January 2009. Conficker exploited MS08-067 and built a botnet of millions of hosts with a domain-generation algorithm that defeated simple takedowns. It provoked the Conficker Working Group, the first large industry-wide coordinated defence.
- — Melissa macro virus running on a test machine. A screen recording showing the Melissa macro virus executing: it mails itself to contacts in the address book and infects further Word documents. Demonstrations like this preserve the behaviour of malware long after the platforms it targeted are gone.
- — Associated Press report on Conficker before April 1. An Associated Press wire report filed on 31 March 2009, the day before Conficker's much-anticipated 1 April activation date. It conveys the uncertainty of the moment: millions of infected PCs, and no agreement on what the worm would actually do.
- — CNN on whether Conficker would strike. CNN's John Sutter is interviewed on the eve of Conficker's 1 April 2009 trigger date about what the worm might do. The segment documents the media build-up around a date that ultimately passed with little visible effect.
- — CBS News on Conficker's later variants. Harry Smith speaks with CNET's Natali Del Conte about Conficker continuing to morph and spread, and its shift toward identity theft. The segment shows how the story moved from a single trigger date to an ongoing criminal infrastructure problem.
- — Documentary on the Code Red worm. A history-of-hacking episode on Code Red, the worm that spread through Microsoft IIS web servers in 2001, and on what the response to it changed. Made long after the event.
- — Demonstration of the ILOVEYOU virus. A run of the ILOVEYOU mail worm in a controlled environment, showing what the script did to files on an infected machine. Useful as a look at the actual artefact rather than a description of it.
- — Malicious Life on the Melissa virus. The Malicious Life podcast episode on Melissa, the 1999 macro virus that mailed itself to contacts from infected Outlook address books and forced companies to shut mail servers down. A researched retrospective.
- — Old malware and the Malware Museum. A look at DOS-era viruses through the Internet Archive's Malware Museum, where defanged copies run in the browser, and at how visibly performative early malware was compared with what came later.
- — Paras Jha and the Mirai botnet. The story of Mirai, the botnet built from IoT devices with default credentials that was used against Krebs on Security, the French host OVH and the DNS provider Dyn in 2016. Its author, Paras Jha, had started out attacking Minecraft servers; the source code was published before the largest attacks.
- — SQL Slammer, the 376-byte worm. In January 2003 a worm exploiting a Microsoft SQL Server buffer overflow spread worldwide in minutes using single UDP packets, saturating networks rather than damaging data. Its speed made it the textbook case for how fast a small payload can propagate.
- — ABS-CBN revisits the ILOVEYOU virus. A Philippine broadcast episode on the ILOVEYOU worm of May 2000, which spread as an email attachment named LOVE-LETTER-FOR-YOU.txt.vbs and overwrote files as it mailed itself onward. It is told from the country where the code was written, where prosecutors found no law under which to charge anyone.

