NexGuard.

← Field Notes · History

A Brief History of the Computer Virus

Before ransomware and nation-state malware, there was a program that just wanted to say hello.

In 1986, two brothers running a computer shop in Lahore, Pakistan, wrote a program to stop customers from pirating their software. Basit and Amjad Farooq Alvi called it Brain, and it did something no one had really seen before: it copied itself, quietly, onto every floppy disk that touched an infected machine. It changed the disk's volume label, hid itself from casual inspection, and spread from computer to computer with no help from its authors. It is widely considered the first virus to infect IBM PC-compatible computers in the wild, and it worked exactly as designed for years after the Alvi brothers stopped caring about the software piracy that inspired it.

The idea predates Brain by over a decade. In 1971, a researcher named Bob Thomas wrote an experimental program called Creeper that moved between computers on ARPANET, the Defense Department network that became the ancestor of the internet, printing the message "I'm the creeper, catch me if you can." It did no damage. It was closer to a magic trick than a weapon: proof that a program could move itself between machines without being carried there by a person. A colleague, Ray Tomlinson, wrote a second program called Reaper whose only job was to hunt down and delete Creeper. It was, in effect, the first antivirus software, built before anyone had a reason to call it that.

What changed the field from a curiosity into an industry was the Morris Worm, released in November 1988 by a Cornell graduate student named Robert Tappan Morris. Morris said later he intended it only to measure the size of the internet. A bug in its replication logic caused it to infect the same machines over and over, and it brought a meaningful fraction of the early internet, then a few tens of thousands of machines, to a crawl within hours. The Morris Worm led directly to the founding of the first Computer Emergency Response Team, at Carnegie Mellon, and to Morris becoming the first person convicted under the newly passed Computer Fraud and Abuse Act.

Commercial antivirus software followed the threat, not the other way around. Companies that would become industry names, McAfee, Symantec, Sophos, all trace their antivirus products back to the late 1980s, built to catch a small and slow-growing number of known threats by checking files against a list. That approach, comparing a file against a catalog of things already known to be bad, is the same basic mechanism underneath every antivirus product sold today, NexGuard included. What has changed since 1986 is not the idea. It is the catalog's size, and the sophistication of what tries to avoid appearing in it.

By the mid-1990s, the volume of new malware had outgrown what a human analyst could catalog by hand, and vendors began layering heuristics and behavioral analysis on top of signature matching, trying to catch what they had not yet seen. That tradeoff, between catching the known with near-perfect accuracy and guessing at the unknown with an acceptable error rate, is the central design tension of the entire field, and it has never fully resolved. It is also, four decades after two brothers in Lahore wanted to stop software piracy, still the first decision every antivirus company has to make.