The History of Malware: From Floppies to Droppers

Eliad Kimhy

BSides NYC 2025 (0x05) · Day 1 · Tech - Other

Overview

Eliad Kimhy's talk, "The History of Malware: From Floppies to Droppers," takes the audience on an engaging journey through the evolution of malicious software, tracing its origins from the early days of personal computing in the 1980s to the sophisticated, financially motivated threats of today. Kimhy, a security researcher at Acronis and former producer of the Malicious Life podcast, meticulously chronicles how malware has adapted to technological advancements, shifting motivations, and the ever-changing landscape of human interaction with computers.

Watch on YouTube

Visual summary for The History of Malware: From Floppies to Droppers by Eliad Kimhy
Visual summary for The History of Malware: From Floppies to Droppers by Eliad Kimhy

Key moments

  1. 0:00 Introduction to the history of malware journey
  2. 2:00 Unveiling the 1989 AIDS Trojan, first ransomware
  3. 2:50 Joseph El Pope's creative floppy disk ransomware distribution
  4. 3:55 AIDS Trojan's ransom note, DOS fake, and file encryption
  5. 5:00 AIDS Trojan's impact and creator's self-surrender
  6. 6:00 The strange trial and release of the AIDS Trojan creator
  7. 7:30 Computers as 'magic' in 70s/80s pop culture

The History of Malware: From Floppies to Droppers

Speakers: Eliad Kimhy, Security Researcher, Acronis

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=k-D9SNmWT3E

Overview

Eliad Kimhy's talk, "The History of Malware: From Floppies to Droppers," takes the audience on an engaging journey through the evolution of malicious software, tracing its origins from the early days of personal computing in the 1980s to the sophisticated, financially motivated threats of today. Kimhy, a security researcher at Acronis and former producer of the Malicious Life podcast, meticulously chronicles how malware has adapted to technological advancements, shifting motivations, and the ever-changing landscape of human interaction with computers.

The presentation serves as a crucial educational resource for both cybersecurity students and seasoned veterans, offering insights into the foundational principles that continue to underpin modern cyber threats. By exploring the inspirations, motivations, and technical ingenuity behind early viruses, worms, and Trojans, Kimhy highlights recurring patterns in the cat-and-mouse game between attackers and defenders. This historical perspective is vital for understanding the present state of cybersecurity and anticipating future challenges, particularly in an era dominated by emerging technologies like artificial intelligence.

Understanding the historical context of malware is not merely an academic exercise; it provides practical lessons for contemporary defense strategies. Kimhy demonstrates that many "new" attack vectors and techniques are often sophisticated iterations of concepts that originated decades ago. From the first ransomware delivered via floppy disk to the proliferation of botnets and crypto-ransomware, the talk underscores the continuous cycle of innovation and adaptation in the adversarial space, emphasizing that fundamental security principles remain relevant despite technological leaps.

Background

▶ Watch: Introduction to the history of malware journey (0:00)

The genesis of malware is deeply intertwined with the early days of personal computing, a period characterized by a sense of wonder and exploration rather than an immediate concern for security. In the 1970s and 1980s, computers were often portrayed in popular culture as magical devices enabling extraordinary feats, from space travel in Star Trek to complex strategic simulations in WarGames. This environment fostered an atmosphere where questions of "what is possible?" took precedence, often overlooking potential negative implications.

A pivotal moment in recognizing the concept of self-replicating code came in 1984 when Alexander Dudney, in a Scientific American column, introduced a game called Core Wars. This game simulated two computer programs battling each other in a shared memory space. Dudney mentioned being inspired by a "fantastical story" about a virus escaping a lab and requiring another virus to hunt it down. While he dismissed it as a "silly story," this myth was, in fact, based on reality: the Creeper program from 1971, developed at BBN Labs, is often cited as the first self-replicating program, designed to demonstrate mobile code. What Dudney didn't anticipate was the deluge of letters he received from readers worldwide, detailing their actual encounters with computer viruses and worms – a testament to the burgeoning, yet largely unacknowledged, threat. By 1989, Dudney's columns reflected a stark shift, quoting Eugene Spafford's grim assertion that "the only safe computer system is one that's switched off, cast in a cement box, put in a room with guards, and even then I have my doubts." This five-year span saw malware transform from a vague concept into an undeniable certainty.

The proliferation of personal computers further accelerated this trend. With the introduction of the Apple II, TRS-80, and Commodore PET in 1977, followed by the IBM PC in 1981, computers became accessible to homes and offices. This "great access" initially came with "zero responsibility," as users explored the capabilities of these machines without a strong security mindset. Crucially, the absence of a widespread commercial internet meant that malware propagation relied on the "sneaker net" – the physical transfer of floppy disks. This necessitated a degree of cleverness and stealth from early malware authors, as their creations had to spread autonomously and often delay execution to avoid immediate detection by human users.

Key Findings

▶ Watch: Joseph El Pope's creative floppy disk ransomware distribution (2:50)

Eliad Kimhy's historical overview reveals several key findings about the evolution of malware, highlighting both the ingenuity of early attackers and the persistent challenges faced by defenders:

  1. Malware Evolution Mirrors Technological Advancement: Each significant leap in computing technology – from personal computers and floppy disks to the commercial internet, Windows operating systems, Office macros, and cryptocurrency – has directly fueled a new wave of malware innovation and propagation methods. Malware authors consistently exploit new functionalities and connectivity paradigms.
  2. Recurring Patterns in Threat Development: The talk identifies a consistent pattern in malware's lifecycle: initial experimentation, followed by whimsical or prank-oriented creations, eventually escalating to destructive and financially motivated attacks. This cycle often repeats with each new technological platform.
  3. Underestimation and Delayed Learning: A recurring theme is the initial underestimation of new threats and a delayed response in developing effective defenses. Examples include the disbelief surrounding early viruses, Microsoft's misplaced confidence in Windows 95's immunity to viruses, and the slow adoption of patching even after major incidents like WannaCry.
  4. The Persistence of "Old" Techniques: Many fundamental malware techniques, such as Trojans (disguising malicious code as legitimate software), macro viruses, and methods of obfuscation, have persisted for decades, merely adapting to new environments. The macro virus, first seen in 1995, continues to be a prevalent attack vector in phishing emails today.
  5. Motivation Shift: From Pranks to Profit: While early malware was often driven by curiosity, pranks, or making a statement (like graffiti), the rise of botnets in the 2000s and cryptocurrency in the 2010s fundamentally shifted the primary motivation to financial gain, giving malware a direct "purpose" in cybercrime.
  6. Key "Firsts" and Milestones: The talk highlights critical historical moments:
  • 1989: AIDS Trojan – The first documented ransomware, demonstrating early ingenuity in blackmailing users.
  • 1982: Elk Cloner – One of the first viruses for Apple II systems, written by a teenager for pranks.
  • 1986: Brain Virus – The first widely reported cross-continental virus, spreading from Pakistan to the U.S., infecting news organizations.
  • 1988: Morris Worm – The first major internet worm, infecting 10% of the ARPANET.
  • 1995: Concept – The first macro virus, demonstrating the power of Office automation for malware.
  • 1998: NetBus / Back Orifice – Early Remote Access Trojans (RATs), showcasing remote control capabilities.
  • 2012/2013: CryptoLocker – The first ransomware to leverage cryptocurrency (Bitcoin) for untraceable payments, fundamentally changing the ransomware landscape.

These findings collectively underscore the dynamic and iterative nature of cybersecurity, emphasizing that understanding its history is crucial for navigating its future.

Technical Deep Dive

▶ Watch: AIDS Trojan's ransom note, DOS fake, and file encryption (3:55)

The technical evolution of malware, as detailed by Kimhy, is a fascinating chronicle of ingenuity adapting to technological constraints and opportunities.

In the 1980s, with nascent personal computing and the prevalence of the "sneaker net," malware focused on low-level system interaction and stealth. Boot sector viruses were common, such as Elk Cloner (1982) for Apple II systems. These viruses would infect the boot sector of a floppy disk, ensuring their code executed first when the computer started. Upon execution, they would copy themselves to the system or other disks, spreading as users shared floppies. Another common technique was program appending, where the virus code would attach itself to an executable. When the legitimate program was run, the virus would typically modify the program's entry point to jump to the virus code, execute its malicious payload, and then jump back to the original program's entry point, making its presence difficult to detect without careful inspection. Early viruses also leveraged interrupts, akin to modern system calls, to perform their actions, demonstrating a foundational understanding of operating system interaction.

The speaker highlights the One Half virus (1994) as a particularly clever example of early stealth and destructive capability. This virus would slowly encrypt a hard drive, one sector at a time, upon system reboots or program launches. To avoid immediate detection, it employed a sophisticated trick: if a user attempted to access an encrypted sector, the virus would decrypt it on the fly before the operating system could read it, then re-encrypt it afterward. This ensured the user would not encounter errors until a significant portion of the drive was encrypted, at which point a message, "This is One Half," would appear. Removing the virus at this stage would leave the user with a partially encrypted and unusable drive, forcing a difficult choice. Technically, One Half also demonstrated early forms of polymorphism or metamorphism by splitting its code into empty sectors within a program, making it harder for signature-based antivirus solutions to detect. It also actively sought out and avoided early antivirus programs, a technique still common in modern malware.

The 1990s ushered in the era of the commercial internet and Windows 95, which, despite Microsoft's assurances, opened a "Pandora's box" of new vulnerabilities. The most significant technical development was the rise of macro viruses, enabled by Office 95 and its powerful macros feature. The first proof-of-concept, Concept (1995), appeared just a month after Office 95's release. While Concept merely popped an alert box, its rapid spread (becoming the most common malware within months) demonstrated the immense potential for automation abuse. Later macro viruses, like the Outlaw virus by "Nightmare Joker," showcased increased sophistication. Outlaw would obfuscate its macro names to evade detection by early antivirus programs that relied on known macro signatures. It would also copy itself to global macros, ensuring infection of any new document created. Crucially, Outlaw demonstrated an early form of scheduled, conditional execution: on January 20th, if the 'E' key was pressed, it would take over the screen, display an infection message, and play a dropped sound file of laughter, making for a uniquely "creepy" user experience.

The 1990s also saw the return of worms and the emergence of sophisticated Trojans. The Melissa virus (1999) was a macro virus with worming capabilities. Upon execution of a malicious Word document, it would automatically email itself to the first 50 contacts in the user's address book, leading to widespread email server shutdowns at major companies like IBM and Microsoft. The I Love You virus (2000) followed a similar worming pattern but included more destructive payloads, such as file deletion.

Remote Access Trojans (RATs) became prominent in the late 90s, capitalizing on increased connectivity. NetBus (1998), developed by a Swede, was initially "mischievous," allowing an attacker (client) to control a victim's (server) machine, performing pranks like opening the CD-ROM drive or playing fart sounds. Back Orifice (also 1998), developed by the Cult of the Dead Cow, was far more malicious, offering capabilities like file deletion and movement. A significant leap came with Sub7, which introduced the ability to communicate back to an IRC (Internet Relay Chat) server for command and control (C2). This allowed attackers to manage multiple infected machines from a central, albeit indirect, location, laying the groundwork for botnets.

The 2000s were defined by the dominance of botnets, which integrated worming capabilities, Trojans, and C2 infrastructure. Early botnets would spread via email, IRC, or file-sharing platforms, often dropping downloaders that fetched additional malicious modules from the internet. These downloaders would install backdoors or RATs that communicated back to hard-coded C2 servers. While blocking these hard-coded IP addresses could "kill" a specific malware variant, attackers rapidly iterated, releasing new versions with different C2 addresses. This rapid iteration led to a dynamic, real-time adversarial exchange, as illustrated by the Nearbot example, where malware authors directly communicated with researchers identifying their creations. Botnets provided a scalable platform for cybercrime, enabling services like Distributed Denial of Service (DDoS) attacks, spam campaigns, and eventually, banking Trojans that stole financial information.

The 2010s marked a paradigm shift with the advent of cryptocurrency, notably Bitcoin (created 2008/2009). The CryptoLocker ransomware (2012/2013) was the first to leverage Bitcoin for ransom payments, providing attackers with a pseudonymous and largely untraceable payment mechanism. This removed a major hurdle for financially motivated cybercriminals and fueled the explosion of ransomware. Concurrently, large-scale vulnerabilities like EternalBlue (a leaked NSA exploit) led to devastating global incidents like WannaCry (2017), demonstrating how sophisticated exploits could be weaponized for rapid, widespread infection and ransomware delivery, affecting millions of systems globally.

Demo / Proof of Concept

▶ Watch: The strange trial and release of the AIDS Trojan creator (6:00)

While the talk itself did not feature a live, interactive demonstration of malware, Eliad Kimhy effectively described numerous historical proofs-of-concept and their operational mechanisms. For instance, he detailed how the AIDS Trojan in 1989 functioned by encrypting files and printing a ransom note, essentially demonstrating the world's first ransomware. The Concept macro virus (1995) was explicitly a proof-of-concept, showcasing how a simple macro could spread rapidly through Microsoft Office documents. Furthermore, the description of early Remote Access Trojans like NetBus and Back Orifice vividly illustrated their capabilities, from opening CD-ROM drives to full file system control, serving as historical demonstrations of remote access and control.

Defensive Implications

▶ Watch: Computers as 'magic' in 70s/80s pop culture (7:30)

The historical journey through malware offers profound and often unsettling lessons for contemporary cybersecurity defenders. Many of the challenges faced today are echoes of past battles, merely amplified by scale and technological sophistication.

Firstly, the talk underscores the critical importance of patching and vulnerability management. The WannaCry incident in 2017, fueled by the EternalBlue vulnerability, infected millions despite patches being available. This highlights a persistent failure to apply fundamental security hygiene, demonstrating that even sophisticated, nation-state-level exploits can be mitigated by basic, timely updates. Defenders must prioritize robust patching programs and ensure they reach all assets, especially legacy systems.

Secondly, the history of malware reveals that "convenient" features often become powerful attack vectors. The case of Office macros is a prime example; designed for automation, they quickly became a dominant mechanism for malware delivery and remain so today, nearly three decades after the Concept virus. This pattern extends to other functionalities, such as the ability to run commands from an Explorer address bar in Windows, initially conceived as a "cool feature" but later abused for PowerShell attacks. Defenders should exercise extreme caution with features that offer extensive automation or system interaction, scrutinizing their default configurations and potential for misuse. User education about macro security and enabling "macro-free" defaults are essential.

Thirdly, the persistence of basic vulnerabilities, such as weak passwords, as exploited by the Morris Worm in 1988, serves as a stark reminder that human factors remain a significant weak link. Despite decades of awareness, weak or reused passwords continue to be a primary vector for initial access. Implementing multi-factor authentication (MFA) and strong password policies is not just good practice but a historical necessity.

Fourthly, understanding the evolution of Command and Control (C2) mechanisms is vital. Early malware used hard-coded IP addresses, allowing defenders to block them effectively. However, malware authors quickly adapted to more resilient methods like IRC servers (as seen with Sub7), and modern threats use diverse techniques including domain generation algorithms (DGAs), legitimate cloud services, and peer-to-peer networks. Defenders need adaptable threat intelligence and network monitoring capabilities to detect and disrupt various C2 channels.

Finally, the talk emphasizes that antivirus evasion is an old trick. The One Half virus in 1994 already looked for and avoided antivirus programs. Modern malware continues this trend with sophisticated obfuscation, packing, and anti-analysis techniques. This means defenders cannot rely solely on signature-based antivirus. A multi-layered defense strategy, incorporating endpoint detection and response (EDR), behavioral analysis, network segmentation, and proactive threat hunting, is indispensable. The ongoing cycle of "whimsical experimentation" leading to "malicious nastiness" with each new technology, such as AI, suggests that defenders must constantly anticipate how new capabilities can be weaponized and build in security from the ground up, rather than retrofitting it.

Key Takeaways

  • Malware Evolution Mirrors Tech Progress: Malware continuously adapts to and exploits new technological advancements, from floppy disks and the "sneaker net" to the commercial internet, Windows, Office macros, and cryptocurrency.
  • Recurring Patterns of Exploitation: Each new technology often follows a similar pattern: initial experimental or whimsical abuse, which then escalates to destructive and financially motivated attacks as attackers discover its full potential.
  • "Old" Techniques Persist and Adapt: Fundamental attack vectors like Trojans and macro viruses (first seen in 1995) remain highly effective today, demonstrating the longevity and adaptability of basic malicious concepts.
  • Cryptocurrency Revolutionized Ransomware: The introduction of Bitcoin enabled the first truly profitable ransomware (CryptoLocker, 2012/2013) by providing a pseudonymous payment mechanism, fundamentally shifting attacker motivations towards direct financial gain.
  • Lessons Often Go Unlearned: History shows a consistent pattern of underestimating new threats and failing to implement basic security hygiene (like patching or strong passwords) even after major, widespread incidents.
  • Anticipate AI as the Next Frontier: Just as past technologies were weaponized, future malware will likely leverage emerging capabilities like Artificial Intelligence for autonomous threat generation, penetration testing, and evasion, requiring proactive defensive strategies.

About the Speaker(s)

Eliad Kimhy is a Security Researcher at Acronis, a global cybersecurity and data protection company. In his role, he contributes to understanding and mitigating current and emerging cyber threats. Kimhy is also well-known for his work as a producer and former producer of the popular podcast Malicious Life, which delves into the history of cybersecurity and the human stories behind significant cyber incidents. His expertise spans a broad range of cybersecurity topics, with a particular focus on threat research, as evidenced by his involvement with Acronis's threat research initiatives (acronis.com/true), where he covers various threats including nation-state attacks.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent, well-structured historical survey of malware evolution that works as an educational primer for students or practitioners new to the field. Kimhy clearly knows the material, but this is a curated retrospective — not original research — and BSides NYC deserves to know the difference.

Heather Calloway (CISO) — WEAK

Technically competent history lesson that never crosses into governance, accountability, or operational decision-making. Well-organized and accessible, but it delivers context without consequence — and context alone doesn't change how programs are run.

→ Top-rated talks at BSides NYC 2025 (0x05)

All talks from BSides NYC 2025 (0x05)