Skip to playerSkip to main content
Computer viruses have caused billions of dollars in damage and disrupted businesses, governments, and everyday users around the world. In this video, we explore 6 of the most dangerous and infamous computer viruses in history, how they spread, what made them so destructive, and the impact they left on cybersecurity.

From fast-spreading malware to attacks that changed the way people think about digital security, these viruses offer important lessons about staying safe online.

Watch until the end to discover the stories behind some of the most notorious computer viruses ever documented.



#ComputerViruses #CyberSecurity #Malware #ComputerSecurity #TechExplained #CyberAttack #InternetSecurity #Technology #Virus #MalwareHistory #CyberThreats #TechHistory #DigitalSecurity #ComputerHistory #Dailymotion

Category

🏖
Travel
Transcript
00:00Ryuk. On October 1st, 2019, three hospitals in Alabama suddenly lost access to critical
00:06computer systems used in patient care. The cause was a strain of ransomware known as Ryuk,
00:11one that would ultimately end up claiming far more than just stolen files and data.
00:15Ryuk had infected the network of DCH Health System, locking staff out of critical digital
00:19systems at DCH Regional Medical Center, at Northport Medical Center, and Fayette Medical Center.
00:24It got bad enough that the hospitals began turning away non-critical patients,
00:28while ambulances were redirected to other facilities whenever possible.
00:31In extreme cases, some scheduled procedures had to be postponed while staff fell back on
00:36manual paper-based systems. But the DCH Health System wasn't the first place Ryuk had hit.
00:41Ryuk had already been targeting large organizations for more than a year,
00:45shutting down critical systems and demanding huge ransoms. The virus first appeared publicly in
00:50August 2018. In some of its earliest known attacks, affected organizations were being asked for
00:55anywhere between 15 and 50 Bitcoin. And even this early on, the attackers had already managed
01:00to collect more than $640,000. But when researchers began pulling Ryuk apart, its code seemed strangely
01:07familiar. Large portions of its encryption system closely resembled another ransomware strain called
01:12Hermes, which raised a much bigger question about where Ryuk had come from.
01:16Hermes had previously appeared during a 2017 cyber attack against Taiwan's Far Eastern International
01:21Bank. The attack was linked to a notorious North Korean hacking operation known as the Lazarus
01:25Group. So when Ryuk appeared carrying code that looked disturbingly similar, researchers naturally
01:30began wondering whether North Korea might be involved again. But the connection wasn't that simple.
01:35Further investigation showed that Hermes wasn't exclusive to the Lazarus Group.
01:39Its ransomware code had circulated among multiple cybercriminals, so the similarities between Hermes and
01:44Ryuk were not enough to establish a North Korean origin. And as researchers looked further into Ryuk itself,
01:49the evidence began pointing somewhere else. The infrastructure, infection methods, and operators
01:54behind the attacks were increasingly tied to Wizard Spider, a Russian cybercriminal group already known
01:59for running notorious banking malware. Unlike a state-backed operation designed primarily for
02:04espionage or sabotage, Wizard Spider's goal with Ryuk was much simpler, money. Ryuk was built around what
02:10became known as big game hunting. Instead of infecting thousands of random home computers and asking each
02:16victim for a few hundred dollars, its operators went after organizations with large networks,
02:21valuable data, and far more to lose if those systems suddenly went offline. The attacks often
02:25started with phishing emails designed to plant malware inside a victim's system within an organization.
02:30Once someone inside that organization opened the wrong attachment, malware could give the attackers
02:34away into the network. From there, they could steal credentials, move through different systems,
02:38and work their way toward the machines that mattered most. And as soon as they had control over the
02:42entire system, the attackers would leave behind a disturbing ransom note.
02:46Your business is at serious risk. There is a significant hole in the security system of your company.
02:51We've easily penetrated your network. You should thank the Lord for being hacked by serious people
02:56and not some stupid schoolboys or dangerous punks. You have to pay for decryption in bitcoins.
03:01The final price depends on how fast you write to us. Every day of delay will cost you an additional
03:060.5 bitcoins.
03:07And over the next few years, versions of that ransom note would appear inside organizations
03:12around the world. Ryuk would eventually be used against thousands of organizations,
03:16ranging from private companies and local governments to school districts, critical
03:20infrastructure, and hospitals. By it, healthcare would by far become one of its most dangerous
03:24targets. In July 2019, Spring Hill Medical Center in Mobile, Alabama was hit by a ransom attack
03:30that knocked most of its computer network offline for more than three weeks. Although the hospital
03:35itself never publicly confirmed the name of the virus, analysts believed it was a variant of the
03:39Ryuk malware. As a result, most of the hospital's internal communications were disrupted. But the
03:45most critical impact was inside the labor and delivery ward where nurses could no longer use the
03:49central screen that displayed fetal heart rate monitors from multiple rooms. Eight days into that
03:54outage, a mother named Tyranny Kid arrived at the hospital to give birth to her daughter. During the
03:59delivery, her daughter's heart rate began unknowingly showing signs of distress. She was
04:03eventually born with her umbilical cord wrapped around her neck, depriving her brain of oxygen and
04:08leaving her with severe brain damage. She died nine months later, and Tyranny sued the hospital on the
04:13grounds of the cyber attack preventing the staff from recognizing the problem and intervening earlier.
04:17Although the case was settled in 2024, it became the first alleged ransomware-related death in the
04:23US. Unfortunately, from there on, the attacks only kept getting bigger. By June 2021, Ryuk had been
04:29linked to attacks on at least 235 hospitals and psychiatric facilities, along with dozens of
04:35other healthcare providers. In September 2020, Ryuk struck Universal Health Services, triggering a
04:40network shutdown across all 250 of its US facilities. And it came at one of the worst possible times.
04:47Hospitals were already stretched by the pandemic, and now even routine patient care had become a
04:51nightmare to manage. By the time the damage was counted, United Health Services estimated the attack
04:56had cost the company around $67 million in lost revenue and recovery expenses. The threat became
05:02so severe that by October, the FBI, CISA, and Department of Health and Human Services issued a
05:08joint warning to hospitals across the country, specifically warning about ransomware attacks,
05:12including Ryuk. Even outside healthcare, Ryuk was causing enormous damage. That same month,
05:18a French technology company named Sopra Asteria was hit by a previously unknown version of the Ryuk virus.
05:23The company managed to contain it, but restoring its systems took weeks, and the disruption was
05:28estimated to cost between 40 and 50 million euros. Meanwhile, the people behind Ryuk were making
05:33millions from these attacks. By early 2021, researchers had followed the money across 61
05:38Bitcoin addresses tied to Ryuk, revealing that the attackers had already collected more than $150
05:43million in ransom payments. By it, this money also left a trail. Investigators were eventually able
05:49to trace some of the ransom payments through the people helping Ryuk's operators convert and launder
05:53the Bitcoin. That led to arrests, extraditions, and guilty pleas, including people directly involved
05:59in laundering the proceeds of Ryuk's attacks. By it, the wider operation didn't simply disappear.
06:04Ryuk itself eventually faded from the spotlight, but the core model behind it continues to operate
06:09under different names with the same objective, paralyze the system, then hold its survival hostage for a price.
06:20By 2010, tensions around Iran's nuclear program had been building for years. Years of inspections,
06:27negotiations, and sanctions had made Iran's nuclear facilities some of the most closely watched in the
06:32world. By it, while all of this was playing out publicly, something far more unusual was already
06:36happening inside Iran's largest uranium enrichment facility, Natanz. In late 2009 and early 2010,
06:43centrifuges inside the tin suddenly began spinning out of control. Centrifuges are machines used to
06:49separate uranium isotopes. They spin uranium gas at enormous speeds, and a violent failure could
06:54expose workers to dangerous chemicals on a large enough scale that could injure or kill people inside
07:00the facility while knocking a significant part of the country's uranium enrichment capability offline.
07:05But to the Iranian scientists watching the control systems, nothing appeared to be wrong.
07:09There were no alarms, and the control room screens continued to display normal readings.
07:14Meanwhile, the centrifuges themselves were being damaged. By the time the scale of the attack became
07:19clear, close to one-fifth of Iran's operating nuclear centrifuges were destroyed. But the machines
07:24weren't simply failing on their own. Someone had managed to infect the facility with a highly
07:28sophisticated piece of malware called Stuxnet. What was particularly dangerous with this virus,
07:34unlike ordinary malware, was that it didn't just infect every computer it reached.
07:37It searched for a very specific configuration of industrial equipment. Unless it found the
07:43systems it had been designed for, its destructive payload would remain inactive. Which meant,
07:48Stuxnet was a cyberweapon specifically designed to sabotage Iran's uranium enrichment program.
07:53And whoever created it had apparently been working on the attack for years.
07:57Researchers later uncovered an earlier version of Stuxnet dating back to 2007,
08:01showing that the malware had existed years before it was publicly discovered in 2010.
08:05Throughout this time, Stuxnet was repeatedly modified until it eventually evolved into the
08:10version the scientists and the TANs were now dealing with. One that could directly change
08:14the speed of the centrifuges while making everything appear normal on their screens.
08:18By it, Stuxnet was only one part of a much larger covert campaign targeting Iran's nuclear program.
08:23On the morning of November 29th, 2010, two scientists connected to the country's nuclear work
08:28were targeted in nearly simultaneous bomb attacks.
08:31Majid Shariari was killed while Feridun Abassi Davani survived a separate explosion.
08:37And although it was never officially confirmed who was behind the attacks,
08:41they were widely attributed to the intelligence agencies of the US and Israel.
08:44An operation as sophisticated as Stuxnet was unlikely to have been the work of ordinary cybercriminals.
08:50It required detailed knowledge of the TANs and the machinery inside it.
08:54Everything about it pointed toward an operation backed by the resources of a state.
08:58But even with those resources, getting Stuxnet into the TANs wasn't easy.
09:02The facility was heavily isolated from the outside world, and the computers controlling
09:06the centrifuges were disconnected from the internet, so Stuxnet couldn't simply be sent
09:10into the facility remotely. Instead, the virus is believed to have crossed that barrier through
09:14infected USB drives carried in by people with access to the facility.
09:17Once those drives were plugged into a computer inside the TANs, Stuxnet began quietly spreading
09:22throughout the internal network. It was searching for a very specific control system used to
09:26operate the machinery running the centrifuges. And when it finally found that system,
09:31Stuxnet finally started to carry out the sabotage the engineers had been witnessing all along.
09:35By the time the full scale of the damage became clear, Iran's nuclear program was set back by
09:40two years. And although the malware was specifically designed to attack the Iranian nuclear program,
09:46it didn't remain there. Due to a programming error, Stuxnet escaped the TANs facility and leaked
09:50out onto the public network. It aggressively spread across the globe, eventually infecting over
09:55200,000 computers across more than 100 countries, including the United States. However, despite
10:01spreading that far, most of those computers were never damaged. Stuxnet would remain harmless unless
10:06it found the exact control system it had been designed to attack. In a way, that made what
10:10happened at Natanz even more unsettling. Even though the virus had spread across the world,
10:15it was still searching for one very specific type of target. Eventually, the vulnerabilities Stuxnet
10:20relied on were patched, and the worm itself had been programmed to self-destruct in June 2012.
10:25By that point, stopping Stuxnet was only part of a much bigger problem. Once its code escaped onto
10:30the public internet, anyone with bad intentions could potentially adapt its methods for another
10:34target. In the end, Stuxnet had left behind the dangerous blueprint for future attacks on
10:39industrial systems, proving that something as invisible as computer code could reach into the
10:44physical world and damage the infrastructure entire industries depended on.
10:50Once a virus gets access to your computer, the damage doesn't necessarily stop at your files.
10:55It can expose some of your most personal information, and once it's out there, you have very little
11:00control over where it ends up. Think about everything on your computer right now. Photos, passwords,
11:06financial information, personal documents. I would never want any of that getting into the wrong hands.
11:10By it, the uncomfortable truth is, most of your information is most likely already out there.
11:16Because while you can protect yourself from viruses by simply avoiding sketchy websites or weird emails,
11:21there's nothing you can do about data brokers collecting and selling your information like
11:25your name, address, and phone number. This is what led me to Aura, the sponsor of this video.
11:30To me, the most valuable feature Aura offers is automatically opting me out of data broker sites
11:35so my information stays protected. By it, Aura also has a whole host of other key features,
11:40like monitoring the dark web, monitoring my bank and credit accounts for fraud,
11:44providing an antivirus, VPN, and password manager, along with many others.
11:48Aura's a US-based company whose business is to keep your personal information protected,
11:53not pawning it off to some shady company for a quick buck.
11:56Aura also works 650 times faster than their competitors, warning you before criminals even
12:00have a chance to finish placing a fraudulent order. Your data is literally being sold as I'm
12:05talking to you. Visit Aura.com slash chilling scares, also linked in the description,
12:10for a 14-day free trial to keep yourself protected and reduce spam.
12:15WannaCry
12:16On May 12th, 2017, a devastating cyber attack began paralyzing computers around the world.
12:22The virus was called WannaCry. It was a type of ransomware that attacked computers by locking
12:27down critical files and demanding payment in Bitcoin to unlock them. After the virus took effect,
12:33the hacked computer screens displayed a disturbing pop-up message saying,
12:36Your important files are encrypted. We guarantee that you can recover all your files safely and
12:41easily, but you have not much time. It then demanded a payment of $300,
12:46warning that the amount would double if the victim failed to pay within three days.
12:50In a desperate attempt to recover their files, many people began paying the ransom amount,
12:54only to find out that the ransom system itself was flawed. The attackers were using just three
12:59hard-coded Bitcoin addresses, with no reliable way to know which infected computer a payment had
13:04come from. So, even if a victim paid the ransom, there was no reliable system to identify them and
13:09send back the correct key needed to unlock their files. What made things worse was that WannaCry
13:13was built around an exploit called EternalBlue. This exploit was originally developed by the US
13:18National Security Agency for its own hacking operations, but it was stolen and leaked online by a
13:23hacking group known as the Shadow Brokers. Once EternalBlue was released publicly, anyone capable
13:28of using it suddenly had access to a powerful tool for breaking into vulnerable Windows computers.
13:33And before long, that weapon would become a part of the WannaCry virus. Investigators later linked it
13:39to Lazarus, a North Korean hacking group. By December 2017, both the US and UK governments had
13:45formally blamed North Korea for creating and spreading the malware. But what made the virus so
13:50dangerous was the way it spread. Most ransomware relies on someone clicking a malicious link,
13:55opening an infected attachment, or downloading something they shouldn't. By the WannaCry didn't
13:59need any of that to keep moving from one computer to the next. It exploited a vulnerability in Windows
14:04SMB, or server message block, which is a system that allows computers to communicate and share files
14:09with each other over a network. Once it reached a vulnerable machine, it could begin searching for
14:14other vulnerable computers and infect them automatically without anyone realizing what was happening.
14:18And it did exactly that at a frightening speed. Within 24 hours, the WannaCry virus had infected
14:24roughly 200,000 computers, eventually reaching more than 150 countries around the world. Major
14:29manufacturing plants were hit by massive production outages. And automobile giants like Honda, Renault,
14:36and Nissan had to temporarily halt production at several factories. But the most serious consequences
14:41were left in the healthcare system. In the UK, the virus severely disrupted the National Health Service,
14:46affecting tens of thousands of devices across hospitals, including computers and medical equipment.
14:51These weren't just administrative systems. Doctors and hospital staff relied on attacks as patient data,
14:57schedule appointments, and keep track of people already receiving treatment. So once those systems
15:01were locked, some hospitals were forced back to pen and paper just to keep basic services running.
15:05From there, the disruption began affecting patients directly. Around 19,000 appointments were cancelled as a
15:11result of the attack, leaving thousands of people unable to receive urgent care when they needed it.
15:15At some affected hospitals, ambulances had to be diverted because staff could no longer access the
15:19patient information they needed. By this point, WannaCry had become more than just a cyber attack on
15:24computers. For some patients already in need of critical care, the disruption meant the difference
15:29between life and death. But before the situation could get much worse, something unexpected happened.
15:34The same day the virus was unleashed, its rapid spread suddenly began to slow after a 22-year-old
15:39security researcher named Marcus Hutchins discovered a kill switch buried inside the malware.
15:43While examining its code, Marcus noticed a strange web address buried inside it.
15:48At first glance, it looked like nothing more than a random string of characters.
15:51But as he looked closer, Marcus realized that the virus was programmed to contact this address
15:56before it began encrypting a computer. He tried opening it and discovered that the domain didn't exist.
16:01So he registered it for less than $11. What Marcus didn't know was that by bringing that address
16:06online, he had triggered a kill switch buried inside the malware. Before infecting a computer,
16:11the WannaCry virus was programmed to check whether that strange domain was online.
16:15Up until that point, the address didn't exist, so every time the malware checked it,
16:19there was nothing there. But the moment Marcus registered the domain, the malware started getting
16:24a response whenever it checked the address. This ultimately stopped the virus from spreading any
16:28further. It was an incredibly simple ending to a virus that had spent the previous hours tearing
16:34through hundreds of thousands of computers around the world. But once researchers understood what Marcus
16:39had accidentally triggered, it raised another important question. Why had the attackers built
16:43something like this into the virus in the first place? There are several theories around what this
16:47kill switch was actually meant to do. One theory suggests it was exactly what it looked like,
16:52an emergency switch that could shut the virus down if the attackers ever needed it to.
16:56But Marcus himself believed there was another explanation. He thought the domain was actually
17:00designed to protect WannaCry from security researchers. Researchers often test malware inside
17:05sandboxes or simulated computer environments where even non-existent websites can appear active.
17:10So, if the virus contacted an address that should have been offline and still got a response,
17:15it could recognize that it was being watched and shut itself down. Whatever the real explanation was,
17:19Marcus had brought the main outbreak under control. By then, the damage had already been done.
17:24The files that were infected by the ransomware could not be recovered, and for many everyday
17:28people and organizations, important data was permanently lost. The virus ended up causing an estimated
17:34loss of $4 billion around the world, despite only being active for less than a day. Looking back,
17:39there was no way to know how much further the malware might have spread. Had Marcus not discovered
17:43the kill switch when he did, the financial losses could have exceeded far beyond $4 billion,
17:48and hospitals could have stayed crippled for much longer, putting people who depended on urgent
17:52treatment or life-saving equipment in even greater danger.
17:59NotPetya
18:00On June 27th, 2017, computers across Ukraine suddenly began going dark. A destructive piece of malware
18:07called NotPetya was spreading through the country, locking people out of their own computers.
18:11At first, it looked like another ransomware attack, with all the infected screens displaying the same
18:16message.
18:16Oops, your important files are encrypted. Perhaps you're busy looking for a way to recover your files.
18:22Don't waste your time. Send $300 worth of bitcoin to the following address.
18:26But when some victims actually tried to pay the ransom, they discovered something was wrong.
18:31The attacker's email address had already been suspended. So, even if they paid the $300,
18:36there was no way to send the required confirmation to recover their data. Which meant, in reality,
18:40the $300 ransom was just a disguise for something far more organized and destructive.
18:45This wasn't the first time Ukraine had gone through a cyber attack like this.
18:49In 2015, and again in 2016, similar cyber attacks knocked parts of its power grid offline.
18:55Across the two attacks, roughly 400,000 people of Ukraine lost electricity and were left in the
19:00brutal winter conditions. Those attacks, and NotPetya itself, were later attributed to Russia's military
19:06intelligence agency, the GRU. In 2020, the US Department of Justice handed out criminal charges against
19:12six Russian military intelligence officers responsible for the attack. And upon further
19:16investigation, it was found that NotPetya wasn't really ransomware at all. It was a wiper malware,
19:22a type of computer virus built to destroy data rather than hold it for payment. Once it spread
19:26through a system, it could scramble critical files beyond recovery, leaving victims with almost no way
19:31to undo the damage. The entire purpose of the deadly virus was to cripple a country by targeting its
19:36government, financial, and energy systems and leaving as much destruction as possible in its
19:41path. And to cause that kind of damage, NotPetya first needed a way into the systems it was built
19:46to destroy. One of the main entry points for the virus was ME-DOC, a trusted Ukrainian accounting
19:51software popularly used by businesses across the country for handling taxes. But weeks before the
19:57June 27th update, hackers compromised ME-DOC servers and planted NotPetya inside its update mechanism.
20:03So, when the update finally went live, the software unknowingly delivered the virus straight to every
20:08computer that downloaded it. After that, it could spread through the organization's network at an
20:12unsettling speed. From there, NotPetya could steal login credentials and exploit weaknesses in Windows
20:17to jump between machines across the organization. And this is where the attack became much harder to
20:22contain. With that terrifying speed and contagiousness, NotPetya was tearing through entire networks on its
20:28own, crippling computer systems within seconds before anyone had a chance to stop it. For
20:32example, it took down the entire system of a large Ukrainian bank in only 45 seconds and fully
20:37infected part of a Ukrainian transit hub in only 16 seconds. The attack also hit some of the more
20:42crucial infrastructures, like the Chernobyl nuclear plant, where it knocked out the Windows-based system
20:47used to automatically monitor radiation levels. For a time, workers had to measure them manually
20:52instead. As the effects of NotPetya became more widespread, the malware escaped Ukraine and
20:56spread to 64 other countries, including Russia itself. But the biggest impact of the destructive
21:02malware was seen on the massive ocean shipping container line Maersk. The infection caused a
21:07global operational paralysis as 17 automated terminal gates at Maersk went down, preventing shipping
21:12trucks from entering or leaving. There were miles of 18-wheeler trucks idled outside these terminals,
21:18while container ships carrying thousands of tons of cargo were left waiting out at sea as ports
21:22struggled to process them. It was an eerie sight. One of the most advanced shipping networks in the
21:27world had effectively been dragged decades backwards overnight. To keep cargo moving during the blackout,
21:33port workers were forced to manually record where containers were supposed to go, while office staff
21:37resorted to personal emails and WhatsApp just to keep communication. The United States would later
21:41describe NotPetya as the most destructive and costly cyber attack in history, with estimates placing the
21:47total damage at roughly $10 billion. But perhaps the most unsettling part was what researchers
21:53discovered afterward. They could find ways to stop NotPetya before it struck. But once it had already
21:58destroyed a machine's data, there was no hidden key, ransom payment, or reliable way to bring those
22:03files back. That was because NotPetya had never really been built like ordinary ransomware. It was a
22:09weapon of state-sponsored sabotage disguised as common cybercrime. And by the time the world realized
22:14what it really was, major parts of Ukraine's economy had already been crippled, while businesses and
22:19critical systems around the world were left in ruins.
22:25Bad BIOS
22:27In 2010, a network security researcher named Dragos Roya began noticing something strange in a MacBook Air
22:33in his lab. He had just installed a fresh copy of Mac's operating system when the computer began updating
22:39its own firmware during the startup. Soon after, the machine refused to boot from a CD, began undoing its
22:44configuration changes and deleting data on its own. At first, Dragos didn't know what was causing the
22:49disruption, so he wiped his entire system clean and restarted. By it, the strange behavior eventually
22:54came back, and this time it wasn't limited to just the MacBook. Over the following months, Dragos began
23:00seeing similar problems on other machines in his lab, including computers running Windows and Linux
23:04operating systems. One case that specifically caught his eye was a machine sending network traffic
23:09through IPv6, even though IPv6 wasn't enabled on the computer. In simple terms, the computer was
23:15still communicating through a network protocol that was switched off. At this point, Dragos knew he
23:20wasn't dealing with an ordinary software problem, so he began isolating the affected computers through
23:24a technique called air gapping, which just means physically disconnecting them from the rest of the
23:28network. He disconnected Ethernet cables, removed Wi-Fi and Bluetooth hardware, and even ran one of the
23:33machines only on battery power to rule out the possibility that it was communicating through the
23:37electrical connection. By it, the bizarre activity somehow still continued. Dragos noticed small
23:43amounts of encrypted data was still moving between an isolated computer and an affected machine nearby,
23:48even though there was no obvious network connecting them. At one point, while searching through the
23:52system registry for signs of the malware, the search function suddenly stopped working, which meant
23:57that whatever Dragos was trying to remove was reacting to his attempts to find it. For three years,
24:02he kept trying to understand what was happening, but the strange behavior never fully went away.
24:06In 2013, Dragos finally made his findings public through a series of Google Plus posts and gave
24:11the suspected malware a name, Bad BIOS. He believed Bad BIOS was infecting the machines at a much deeper
24:17level, possibly inside the BIOS or UEFI firmware that starts before the operating system even loads.
24:23If he was right, reinstalling the operating system was never going to be enough. Whatever was causing the
24:28problem seemed to be hiding much deeper inside the machine. But there were still too much stranger
24:33problems left to explain. First, how was Bad BIOS reaching computers that had been cut off from every
24:38network? By late October 2013, Dragos believed he had found part of the answer. In one of his Google
24:43Plus posts, he wrote,
24:45I lost another one yesterday confirming that simply plugging in a USB device from an infected system
24:50into a clean one is sufficient to infect. That part explained how the infection jumped from one
24:54computer to another even without a network connection. But even that left the biggest mystery
24:59unexplained. Once those computers were infected and completely air-gapped, why were they apparently
25:04still communicating with each other? The answer Dragos gave was even harder to believe. In an October
25:0916th post, he wrote,
25:11So, it turns out that annoying high-frequency whine in my sound system isn't crappy electrical
25:16noise that has been plaguing my wiring for years. It is actually high-frequency ultrasonic
25:20transmissions that malware has been using to communicate to air-gapped computers.
25:24Now, as extreme as all this sounds, some parts of Dragos' theory weren't impossible. Malware had
25:30already reached this deep into computers before. Back in 1998, the CIH virus, also known as Chernobyl,
25:37was capable of overwriting the flash BIOS on vulnerable computers. In some cases, that left
25:41infected machines unable to boot at all. But, the far stranger part of Dragos' story was his claim
25:47that isolated computers were communicating through sound. And even that would soon turn out to be
25:52technically possible. Only weeks after the bad BIOS story became public, researchers at Germany's
25:57Fraunhofer Institute demonstrated that ordinary laptops could exchange small amounts of data using
26:02near-ultrasonic sound through their speakers and microphones. But, while all of the malware's
26:06capabilities could be explained separately, nobody was able to find a piece of malware that could
26:11combine all of them in the way Dragos was describing. And that distinction would eventually
26:15become the biggest mystery with the bad BIOS story. Just days after Dragos' claims received wider
26:20attention, other security researchers began examining the evidence he had collected. One of
26:25them was Arrigo Trielzi. Dragos gave him the BIOS images, disk images, and data from the computers he
26:31believed were infected. But, after going through the material, Arrigo said he couldn't find anything
26:35suspicious. Google security researcher Tavis Ormendy also looked through the evidence and reached a
26:40similar conclusion. More importantly, nobody else was able to reproduce what Dragos was seeing.
26:45That didn't prove that bad BIOS was necessarily fake. But, after years of supposedly surviving
26:51across more than a dozen computers, infecting USB drives, and somehow returning even after systems
26:56had been wiped clean, researchers expected there to at least be a trace. By it, there wasn't. At the
27:01same time, the story itself wasn't easy to completely dismiss either. Bruce Schneer, one of the most
27:07respected names in computer security, said although the claims were extreme, enough respected researchers
27:12were taking Dragos seriously that he wasn't ready to dismiss them either. In the end, no confirmed
27:17malware sample ever surfaced, and no independent researcher proved that bad BIOS could do everything
27:22Dragos described. Which left three possibilities. Either Dragos had encountered an extraordinarily
27:28advanced piece of malware for its time, several unrelated technical problems had been mistaken for
27:34one enormous infection, or bad BIOS had never existed in the first place, and the entire story had been
27:40fabricated. To this day, we don't know which is true.
27:47I love you. On May 4th, 2000, millions of people around the world began receiving love letters in
27:53their inboxes. The emails arrived with the subject line, I love you. Inside was a short message that
27:59read, kindly check the attached love letter coming from me, along with a TXT attachment. What made the
28:05email convincing was that it often appeared to be coming from someone the recipient already knew.
28:09Curious to find out what the love letter said, people opened the attachment, unknowingly falling
28:14for a phishing email carrying a computer worm. The worm was called, I love you. Once opened,
28:19it began corrupting documents, images, and MP3 files stored on the computer. It then accessed Microsoft
28:25Outlook and sent the same email to everyone in the victim's address book. That allowed it to spread from
28:30one trusted contact to another at an alarming rate, becoming one of the most widespread computer worm
28:35outbreaks of the early internet era. I love you was created by Onel de Guzman, a 23-year-old computer
28:41science student in Manila, Philippines. At the time, internet access was expensive, and Onel wanted a way
28:47to get online without having to pay for it himself. So, he developed a malware designed to steal other
28:51people's internet passwords and send them back to him. The attachment was named,
28:57loveletter4u.txt.vbs. Because Windows commonly hid known file extensions at the time, many users only
29:04saw the .txt portion and assumed they were opening an ordinary harmless text file. Once opened, the worm
29:09automatically sent the same email to everyone in the victim's Outlook address book. Because of that,
29:14it didn't stay in the Philippines for long. The virus began spreading through Asia during business
29:19hours on the 4th of May. Within a few hours, it had reached Western Europe, and by early evening,
29:24the United States. In less than 24 hours, more than 45 million computers had reportedly been
29:30infected. It would ultimately reach around 10% of all computers connected to the internet,
29:35making it one of the fastest spreading computer worm outbreaks ever recorded.
29:38But it wasn't just individual users that faced the attack. Government agencies, banks,
29:43media organizations, and even military networks were the ones most affected. And some of the biggest
29:48names got the hardest hit from the virus. At the Pentagon, the outbreak became serious enough
29:53that military personnel had to be pulled away from their regular duties just to help contain and
29:57remove the worm. Some computers were so badly affected that their software had to be completely
30:01reloaded, resulting in the loss of important data. At NASA, the damage went even further. The virus had
30:07disrupted its email system, making it extremely difficult for their staff to communicate warnings
30:11as it spread. It ended up corrupting at least 1,000 files in the system, and while some of them
30:16were
30:16recovered through backups, others were lost permanently. Within hours, a worm created by an undergrad
30:21student had forced both the Pentagon and NASA into damage control. And outside the US, it was
30:27beginning to interfere with the systems that businesses and ordinary people depended on every
30:30day. At the offices of the German newspaper Abendblatt in Hamburg, the virus corrupted their
30:35digital picture archive and ended up destroying around 2,000 photographs. At the time, Abendblatt was
30:41the largest subscription newspaper in northern Germany, selling around 300,000 copies per issue. So,
30:46losing that archive meant that critical news reports were possibly slowed down or delayed.
30:50In Belgium, everyday people were hit the most as ATMs were disabled, leaving citizens unable to
30:56withdraw cash for daily expenses. By the end of its first 10 days, the worm had spread across the
31:00globe and caused an estimated $10 billion in damage. By this point, organizations around the world were
31:06desperately trying to stop the worm from spreading any further, and for some of them, the only option
31:11was to shut email down completely. So, mail gateways were taken offline, and anything carrying the
31:16I love you subject line was blocked before it could reach another inbox. Even then, there wasn't an
31:20immediate fix. Antivirus companies were rushing out updates to detect the worm, but with internet
31:25traffic already overwhelmed, some of them took days to reach the users. Eventually, the spread died down,
31:31and organizations were mostly left cleaning infected computers and restoring whatever they could.
31:36With the virus no longer spreading out of control, attention shifted to the case against
31:40Onel de Guzman. By it, there was a problem. When the virus was released, the Philippines had no law
31:45specifically criminalizing this kind of computer attack. Investigators tried using existing fraud and
31:50malicious mischief laws against them. By it, those laws had been written for completely different
31:54crimes, and none specifically covered the release of a computer virus. Although the Philippines passed a
31:59new law covering computer crimes just weeks after the outbreak, it couldn't be applied retroactively to
32:04something Onel was accused of doing before the law existed. With no applicable law to prosecute him
32:09under, the charges were eventually dropped. So, despite causing billions of dollars in damages
32:13around the world, Onel de Guzman never faced trial for unleashing one of the most destructive computer
32:18worms the world had ever seen.

Recommended