Why Hackers Write Computer Viruses

Why do hackers hack? Why create a worm that sends out an email to everyone in your contact list, or a Trojan that deletes your term papers? Is it mischief, malice, money, or something else entirely?
This is the question that was on my mind when I met with Mikko Hypponen, a legendary computer security heavyweight who has been hunting viruses for 25 years—since Brain.a, the first PC computer virus.
From the plaza, I walked out to a seat by the water facing the San Francisco Bay. Hypponen was there, waiting for me. I sat down next to him. I felt like we needed code phrases.
"What makes this a New Orleans iced coffee," he asked, as he accepted his drink.
"It's the chicory," I replied.
"Did you know the Finns drink more coffee per capita than any other nation?"
"I did know that," I replied. "I know a lot about coffee."
Okay! I guess we had our code phrases after all.
Hypponen is the lead security researcher for F-Secure in Finland. His takedowns and diagnosis include some of the nastiest, biggest computer viruses out there: Sobig.F, Sasser, Storm Worm. PC World called him one of the 50 most important people on the Web. Hypponen was on his way to a black hat conference in Las Vegas.
We met at the Ferry Plaza in San Francisco, sitting by the pier as commuter boats came and went. I wanted to ask him about the long history of personal computer viruses, now in their 25th year, from the simple to Stuxnet, and the shifting motivations that inspire virus writers to act. We had an hour.
The Hobbyists
2011 is the 25th anniversary of the first PC virus. In September, 1986, two brothers from Lahore, Pakistan, Amjad Farooq Alvi and Basit Farooq Alvi, released Brain.a into the wild. Brain.a infected the boot section of computers running PC-DOS. Its authors claimed they were simply trying to target people who were infringing on their own software. But the virus spread wide across the world, and marked the beginning of the malware era in computing.
Late last year, Hypponen was going through his records at F-Secure. He found a box with the 100 first computer viruses, all on floppy disks. "These are probably from five years or more," says Hypponen, "now more than that are written in one hour."
He realized that the first of these, Brain, was approaching its birthday. He had a long history with it, having studied it when it was first unleashed. To mark the anniversary, he travelled to Lahore, Pakistan, in an attempt to track the Alvi brothers down. Amazingly, they still had a business at the same address they had listed in the original Brain.a virus code. So he knocked on the door. They answered.
"They wanted to demonstrate that the PC system was not as secure as Microsoft and IBM said it was," he explains. "They thought it was weak, and [wrote Brain] to demonstrate that."
The Alvi brothers were Unix guys. DOS seemed like a weaker system, and they thought they might be able to exploit it. They wanted to see if they could move code from one system to another, on its own. They wanted to see if it could be transmitted, like a virus.
It worked! Before long the brothers (who had helpfully included their phone number in the code) were getting calls from universities and businesses all over the world, wanting to know what it was.
Others began tinkering with Brain.a, releasing variants. And as time passed, more and more people began writing distinct viruses. These were for the most part, however, more of annoyances than real problems. They might mess up your system but they would not (for most people at least) ruin your life.
And then came email. And that was bad.
"It has changed completely now," says Hypponen. "It changed from hobbyists and old school hackers around 2002 or 2003 when the hobbyists realized they could make money."
The Criminals
By the turn of the century, spam was big business. But in order to send out a lot of spam, you needed a lot of computers. And to keep from getting caught, they shouldn't be your own. Enter botnets.
Viruses allowed spammers to capture and control users computers remotely. They could use infected machines to ensnare other computers, sending out not just offers for herbal viagra, but phishing attacks and keystroke loggers that give them access to bank and financial data and personal information. By 2005, the point of malware writing had largely changed. Fuck proof of concept. Now it's for money.
There's also another reason that malware writers have surged: Microsoft Windows XP. That ancient system is, unbelievably, still the most widely used operating system on the planet. It's installed on more than 50 percent of all machines connected to the Internet, and it's very insecure.
"XP is the weakest of all systems," says Hypponen, " and it is installed on the most computers. Of course you will target that."
"The source of malware today is 99 percent criminal gangs, and that's a pretty nasty development," says Hypponen. "We didn't used to have to worry in the real world. But now there are organized criminal gangs, making millions from their attacks. When we shut down their operations, they know who we are."
It's not just a hypothetical fear. Ivan Eugene Kaspersky, who owns one of the world's leading anti-virus security labs, had his son Ivan snatched off the streets of Moscow earlier this year. Whether there was a revenge motivation, in addition to the ransom, is still unclear. But the fact remains that anti-virus guys are now effectively standing between the mob and big piles of money. Which is never a very safe place to be.
And if that wasn't bad enough, now there's a new, potentially deadlier, source of viruses: governments.
The Spies
"I have Stuxnet right here with me in my bag! Do you want it?"
He leans over and slaps his computer bag on the side. I decline. I know it's not, say, smallpox, but sitting next to the most sophisticated computer virus ever created is oddly worrisome.
Stuxnet upped the ante. It targeted only a certain programming environment, with a certain PLC, with a certain configuration, in a certain location—which turned out to be a nuclear plant in Iran. When it went active, it recorded the normal plant operations for a few days, and then began playing them back to monitors, like a closed circuit tv camera in a bank heist film, while in actuality it was modifying the speed centrifuges spun at, causing them to break apart, most likely in violent fashion. Stuxnet, for now at least, ended Iran's nuclear ambitions.
But where did it come from?
"It was done by your government!" The Finn doesn't have any proof of this, but like most security researchers, he takes it as accepted wisdom.
"I do believe that when in 2008, George W. Bush signed the [Comprehensive National Cybersecurity Initiative] that the end result of that was Stuxnet."
Unlike most viruses, Stuxnet didn't spread over the Internet. Instead, it spreads from one machine to another on infected USB sticks. Which means that somehow, someone had to get an infected stick into physical contact with Iran's nuclear facility in Bushier.
"We don't know how it was originally planted, says Hypponen. "My guess is that they pick-pocketed workers, or broke into their homes and planted them."
Stuxnet has heralded a new era. Today's sophisticated malware attacks might now just target one machine in the entire world. And employee at a certain company could get a virus targets just to that specific person. Governments, corporations, and extremist groups are already engaged in this. As Hypponen points out, Stuxnet had been in the wild for more than a year before anyone discovered it.
What's out there now is an open question.
Hypponen was late for another appointment. And so as we finished our coffees, I stood to leave, and began walking away from the water, back into the plaza. Hypponen stopped me. He reached out his hand, and gave me my iPod, which I'd carelessly left in my seat.
He looked disappointed.
Gizmodo is the world’s most fun technology website, focused on gadgets and how they make our lives better, worse, and more absurd.
Comments
Comments are closed on this article
![]()
essjay22
August 06, 2011 at 2:05pm
I just read this article on Gizmodo and that article had none of the spelling or grammar mistakes this one does. Guys, get a real speelchecker K?
s
![]()
ABouman
August 08, 2011 at 2:02pm
What mistakes are you referring to? We copy straight from Giz, so nothing was altered from the original article as far as content, spelling, grammar... We're happy to correct errors when we see them, especially since our CMS does NOT feature any type of spell check option, which makes it a little harder to catch errors before stories are published live.
![]()
clutchsins
August 05, 2011 at 12:03pm
If I'm not mistaken, I thought the first virus was the cloner virus on the Apple II's?
![]()
MaximumMike
August 08, 2011 at 7:57am
Ummm... I'm pretty sure it didn't run an X86 architecture. Hence, it was not a PC.
![]()
TerribleToaster
August 10, 2011 at 5:56am
Mike is right that Apple II's are not PC's. Because PC's were an IBM product.
But the Apple II is still a computer (called a Home Computer, rather than a Personal Computer) and the Elk Cloner was the first widespread computer virus outbreak, though before that there was the Pervading Animal trojan and before that there was the first virus I know of, the Creeper Virus (which was made as a kind of proof of concept that viruses could be made).
What made Brain special was it was the first PC virus (PC as the IBM PC).
![]()
MaximumMike
August 05, 2011 at 7:22am
Very good article, but I could have done without the F-bomb. For some reason Gizmodo writers seem to thrive on dropping vulgarities in their stories. It brings with it a twinge of unprofessionalism.
![]()
ascendant
August 05, 2011 at 10:20am
I honestly didn't even notice the "f-bomb" until reading the comments about it.
![]()
TerribleToaster
August 05, 2011 at 9:46am
It's seem to stem form that fact that they are solely a blog. MPC does publish some of its articles from here in print (they are a magazine after all) so they seem to have to abide by higher standards.
![]()
codepath
August 05, 2011 at 6:51am
Was he disappointed because you allowed him the opportunity to infect your iPod or because you had the complete Taylor Swift discography on it?
![]()
germanogre
August 04, 2011 at 9:28pm
"Why Hackers Write Computer Viruses"
Money, Notoriety and Vandalism. that simple. it seems that
there is no shortage of people who take pleasure in
wrecking other peoples' property. I have enough to
worry about with teenagers smashing my car windows, or
batting my mailbox.
![]()
DoctorOwl
August 07, 2011 at 7:03pm
Fortunately, you are wrong. This kind of comment is in the same league as, "A priest abused children. Every priest is a child abuser." I am a famous virus writer, or I was two decades ago, and I'm going to give you a history lesson.
In the beginning, there were three kinds of people involved in the computer virus scene; the originals who started everything from the 90s to the early 2000s. We wrote computer viruses as art, and shared source code for the purposes of social bonding on BBSs and IRC. We were not children, not vandals, and did nothing but "write a book" to share secret tricks of narrative and turns of phrase with our closest friends in private networks; long before social media like Facebook was even an idea in someone's imagination. Few of us exist anymore. After a decade, all the art is done, and we've moved onto other things.
Then there are other people who took our work, and spread them on computers. These people have little in common with real computer virus writers. They were mostly curious, and/or stupid kids doing things in a different era where things were different and can't be judged to the same standard as today. I doubt these people exist anymore either, because their source (the original virus writers) have mostly disappeared.
Then there's the third type, which sprouted in the past decade, which is the hardcore hackers doing horrific things with spam, botnet (denial of service) attacks, and scamming people out of money; sometimes (allegedly) through organised crime. Those are the people to be afraid of, and way outnumber those of us originally involved in the art form.
Computer viruses themselves were not malicious, nor were the people that wrote them. But over time, the love of money has corrupted people, which has corrupted the art. Sometimes I feel sad seeing the reputation virus writers now, but it was not always this way.
![]()
SilverSurferNHS
August 04, 2011 at 4:40pm
Didn't know you guys were allowed to publish the word "fuck" in an article unless it was referenced in quotes from a source... so i thought i'd leave mine unsencored as well just to see what would happen :)
![]()
bikerbub
August 04, 2011 at 9:19pm
wouldn't it be sort of silly for a publication to be in favor of net neutrality, but in the same light, advocate censorship?
also, technically, the whole article is quoted, as it is from their sister publication Gizmodo.
![]()
SilverSurferNHS
August 04, 2011 at 10:00pm
i gotta pay more attention to the authors... that makes sense; i was assuming (making an ass of myself!!) that it would be published iin the magazine though, which is where it would be a prob
![]()
avenger48
August 05, 2011 at 9:38pm
I would assume that there is no regulation which prevents them from publishing an f-bomb in a magazine, although their parent company probably wouldn't like it. After all, why would the government censor a word when there are magazines that show uncensored pictures of the deed the word refers to?
![]()
Gezzer
August 04, 2011 at 3:14pm
So who's playing who in the movie adaptation? The iPod bit at the end was priceless. lol
Log in to MaximumPC directly or log in using Facebook
Forgot your username or password?
Click here for help.
















