Skip to main content

ZERO TRUST

A Journey Through Malware: Tracing the Evolution of Cyber Threats

Malware, a portmanteau of “malicious software”, encompasses any software, code, or program designed to harm computers or their users. It is a ubiquitous component of modern cyberattacks, ranging from highly destructive forms like ransomware to relatively harmless annoyances like adware.

Every year, malware attacks inflict billions of dollars in damages on businesses and individuals alike. They can infect devices running various operating systems, including Windows, macOS, iOS, and Android.

Cybercriminals employ malware for a variety of purposes:

  • Extortion: Holding devices, data, or networks hostage in exchange for hefty ransom payments.
  • Unauthorized access: Gaining illegal entry to sensitive data or digital assets.
  • Information theft: Pilfering login credentials, credit card numbers, intellectual property, personally identifiable information (PII), and other valuable data.
  • Infrastructure disruption: Disrupting critical systems relied upon by businesses and government agencies.

While the terms “virus” and “malware” are often used interchangeably, not all malware is a virus. Malware encompasses a broad spectrum of threats, including:

  • Viruses: Malicious programs that cannot spread without human interaction, typically triggered by clicking links, downloading attachments, or launching specific applications.
  • Worms: Self-replicating viruses that spread without human intervention, tunneling through interconnected systems and devices.
  • Botnets: Networks of infected computers controlled by a single attacker, collectively known as the “bot-herder,” acting in unison to carry out malicious activities.
  • Ransomware: A particularly destructive form of malware that encrypts critical data or systems, rendering them unusable, and demands exorbitant ransom payments in cryptocurrency like Bitcoin to regain access.
  • Multi-extortion ransomware: A menacing evolution of ransomware, adding layers of extortion to further pressure victims into capitulating. Double-extortion ransomware encrypts data and steals sensitive files, threatening to release them publicly if the ransom is not paid. Triple-extortion attacks escalate further, threatening to disrupt critical systems or extend the attack to a victim’s customers or contacts.
  • Macro viruses: Malicious code embedded within program files that execute when the corresponding application is opened. Macros are typically used for automating routine tasks within larger applications.
  • Trojans: Deceptive programs disguised as legitimate software or hidden within seemingly harmless files, tricking users into installing them. They can carry various malicious payloads once activated.
  • Spyware: Stealthy programs that infiltrate infected systems to secretly gather sensitive information, such as user browsing habits, keystrokes, and personal data. They often transmit this information back to attackers.
  • Adware: Typically bundled with free software, adware bombards users with unwanted pop-ups, banners, and other advertisements. While mostly benign, some adware may also collect personal information or redirect users to malicious websites.
  • Rootkits: Advanced malware packages that grant hackers privileged, administrator-level access to the operating system or other target assets, enabling them to execute stealthy actions with complete control.

 

While a comprehensive history of malware would be extensive, here are a few notable milestones in its evolution:

 

1966: Theoretical malware’s genesis

Pioneering mathematician and Manhattan Project contributor John von Neumann laid the groundwork for self-replicating programs, laying the theoretical foundation for computer viruses. His work, “Theory of Self-Reproducing Automata,” published posthumously in 1966, laid the groundwork for the concept of malware.

 

1971: The birth of the Creeper worm

Five years after von Neumann’s theoretical work, programmer Bob Thomas created an experimental program called Creeper, designed to travel between different computers on the ARPANET, a precursor to the internet. His colleague Ray Tomlinson, the inventor of email, modified Creeper to not only move between computers but also replicate itself from one to another, making it the first computer worm.

 

1982: Elk Cloner virus emerges

Developed by 15-year-old Rich Skrenta, the Elk Cloner program began as a practical joke. As a member of his high school’s computer club, Skranta gained notoriety for altering games and software shared among members, leading many to avoid disks he touched.

To infiltrate disks he couldn’t access directly, Skranta created the first known Apple computer virus. This boot sector virus, Elk Cloner, spread by infecting Apple DOS 3.3 operating systems and copying itself into the computer’s memory when transferred from an infected floppy disk. When an uninfected disk was inserted, Elk Cloner would copy itself to that disk, quickly spreading among Skranta’s friends. Despite its malicious intent, Elk Cloner could accidentally overwrite or erase some floppy disks. It also included a poetic message:

ELK CLONER:

THE PROGRAM WITH A PERSONALITY

IT WILL GET ON ALL YOUR DISKS

IT WILL INFILTRATE YOUR CHIPS

YES IT’S CLONER!

IT WILL STICK TO YOU LIKE GLUE

IT WILL MODIFY RAM TOO

SEND IN THE CLONER!

 

1986: Brain virus

Prior to the widespread adoption of the Internet, malware primarily spread through physical media like floppy disks. While Elk Cloner, an early virus, affected a relatively small number of computers, the Brain virus, developed by Pakistani brothers Amjad and Basit Farooq Alvi, achieved global reach. Initially intended to combat software piracy, Brain would display a message prompting users to contact the creators to obtain a “vaccination” against the virus. However, the Alvis underestimated the extent of software piracy and were overwhelmed by calls from users around the world.

 

1988: Morris worm

The Morris worm, despite its unintentional destructive nature, marked a significant milestone in the evolution of malware. Created by MIT student Robert Morris, it was initially intended as a proof-of-concept project to demonstrate the potential for self-replicating software. However, due to a programming error, the worm quickly spread across the nascent internet, infecting a significant portion of connected computers.

The worm’s rapid replication consumed excessive memory, causing many infected systems to crash. This incident, the first widespread internet cyberattack, caused widespread disruption and damage, estimated to be worth millions of dollars. Robert Morris was later convicted of cyber fraud, becoming the first person in the United States to be prosecuted for such an offense.

 

1999: Melissa worm

The Melissa worm, released in 1999, demonstrated the power of email-based malware. Unlike previous viruses that spread through physical media or file sharing, Melissa exploited Microsoft Outlook and Exchange email clients, infecting a staggering million accounts and over 100,000 workplace computers.

This worm’s rapid spread caused significant disruptions, overwhelming email servers and slowing down operations at over 300 corporations and government agencies, including Microsoft, the Pentagon’s Computer Emergency Response Team, and a host of other organizations. It became the fastest-spreading worm at the time, highlighting the vulnerability of email systems and the potential for widespread malware infections.

 

2000: ILOVEYOU virus

Driven by financial constraints, 24-year-old Onel de Guzman, a Philippine resident, created the ILOVEYOU virus, a groundbreaking piece of malware that targeted user passwords. This attack marked an early instance of social engineering and phishing. De Guzman exploited human curiosity by disguising malicious attachments as love letters, preying on people’s desire for romantic connections. “I realized that people want a boyfriend, they want to be with each other, they want love,” de Guzman stated.

The worm did more than steal passwords; it also deleted files and resulted in significant damages, temporarily shutting down the United Kingdom’s Parliament’s computer system. Despite being apprehended, all charges against de Guzman were dropped due to a lack of local legal violations.

 

2004: Mydoom worm

The Mydoom worm, like ILOVEYOU, utilized email as a primary vector for spreading infections. Once installed, Mydoom would commandeer infected systems to send out more copies of itself, replicating at an astounding rate. At its peak, Mydoom accounted for 25% of all emails sent worldwide, setting an unbroken record of global spam distribution. The worm’s destructive impact extended beyond spam, as it also formed a botnet to launch distributed denial-of-service (DDoS) attacks. Despite causing billions of dollars in damage, the masterminds behind Mydoom remain unidentified and unpunished.

 

2007: Zeus virus

First detected in 2007, the Zeus trojan infiltrated personal computers through phishing scams and drive-by downloads, highlighting the alarming capabilities of trojan-style viruses that can deliver a wide range of malicious software. In 2011, a significant security breach led to the leak of Zeus’s source code and instruction manual, providing valuable insights for cybersecurity professionals and, unfortunately, also spreading the knowledge among malicious actors.

 

2013: CryptoLocker ransomware

CryptoLocker, one of the earliest ransomware programs, gained notoriety for its rapid spread and powerful encryption capabilities. Utilizing rogue botnets acquired through the Zeus trojan, CryptoLocker effectively encrypted data on infected systems, prioritizing shared resources within local networks like libraries and offices.

To regain access to the encrypted data, CryptoLocker’s creators demanded a ransom of two bitcoins, equivalent to approximately $715 USD at the time. Fortunately, in 2014, a collaborative effort between the U.S. Department of Justice and international agencies resulted in the seizure of the malicious botnet, allowing for the decryption of hostage data without payment. However, CryptoLocker continued to spread through phishing attacks, posing a persistent threat to computer users.

 

2014: Emotet trojan

Emotet, dubbed the “king of malware” by Arne Schoenbohm, head of the German Office for Information Security, exemplifies polymorphic malware, making it a formidable adversary for cybersecurity professionals. Unlike traditional malware that replicates with identical code, polymorphic malware undergoes subtle modifications with each generation, producing variants that maintain the same functionality but differ in their code structure. This complexity hinders the ability of anti-malware programs to recognize and effectively block these evolving threats.

Similar to the Zeus trojan, Emotet remains a persistent threat as a modular program that delivers various forms of malware, often distributed through conventional phishing tactics. Its polymorphic nature and modular structure make it challenging to eradicate, requiring continuous vigilance and robust cybersecurity measures.

 

2016: Mirai botnet

As the technological landscape expands beyond traditional computers to include laptops, mobile devices, and the internet of things (IoT), malware adapts to exploit vulnerabilities in these new environments. The Mirai botnet, created by a college student named Paras Jha, exemplifies this evolution. It targeted IoT devices, particularly weak security-protected CCTV cameras, amassing a vast botnet capable of launching massive distributed denial-of-service (DDoS) attacks.

Initially designed to disrupt gaming servers, Mirai’s capabilities far exceeded Jha’s expectations. It focused its attack on a major DNS provider, effectively disconnecting a significant portion of the United States’ eastern seaboard from the internet for nearly 24 hours. This incident highlighted the growing threat posed by IoT malware and the need for robust cybersecurity measures to protect these interconnected devices.

 

2017: Cyber espionage

Even though malware had been a part of cyber warfare for a considerable time, 2017 marked a significant surge in state-sponsored cyberattacks and virtual espionage. It commenced with the emergence of a seemingly unassuming ransomware named Petya. While initially posing a threat through phishing, Petya wasn’t highly contagious until its transformation into the NotPetya wiper worm. This modified version, masquerading as ransomware, went beyond encryption, destructively targeting user data even if ransom payments were made.

During that same period, the WannaCry ransomware worm made headlines by targeting various prominent entities in Europe, notably impacting the United Kingdom’s National Health Service.

NotPetya is suspected to have links to Russian intelligence, potentially adapted from Petya to target Ukraine. Meanwhile, WannaCry’s origins may be tied to specific adversarial factions within the North Korean government. What ties these malware attacks together? Both capitalized on a Microsoft Windows vulnerability named Eternalblue, initially identified by the National Security Agency. Despite Microsoft eventually identifying and patching the exploit, they criticized the NSA for withholding the information before hackers exploited the weakness.

 

2019: Ransomware-as-a-Service (RaaS)

Lately, ransomware malware has experienced fluctuations in its activity. Despite a potential decrease in successful ransomware attacks, hackers are now aiming at higher-value targets, resulting in escalated damages. A concerning trend on the rise is Ransomware-as-a-Service, which has gained traction in recent times. This service, available on dark web platforms, offers a user-friendly framework where professional hackers execute ransomware attacks for a fee. Unlike previous malware assaults that demanded technical expertise, RaaS provided by mercenary groups empowers individuals with malicious intent and financial resources to engage in such activities.

 

2021: A state of emergency

The first major double-extortion ransomware attack occurred in 2019, targeting security staffing agency Allied Universal. Hackers not only encrypted their data but also threatened to leak the stolen information online. This dual threat meant that even if Allied Universal managed to decrypt their files, they faced the risk of a damaging data breach. While this attack was significant, the 2021 Colonial Pipeline breach gained notoriety due to the severity of its implied threat. The Colonial Pipeline, responsible for nearly half of the eastern United States’ gasoline and jet fuel supply, fell victim to this attack. Lasting several days, the impact extended across public and private sectors along the east coast, prompting President Biden to declare a temporary state of emergency.

 

2022: A national emergency

Despite a potential decrease in ransomware attacks, the threat remains ominous due to the persistence of highly targeted and impactful incidents. In 2022, Costa Rica faced a string of ransomware assaults that began by targeting the Ministry of Finance, subsequently impacting civilian import/export enterprises. Another attack then disrupted the country’s healthcare system, directly affecting virtually every citizen. Consequently, Costa Rica entered the annals of history as the first nation to declare a national state of emergency in response to a cyberattack.