July 29, 2026
The Next 10 Malware Programs in Computer History
From shape-shifting viruses to a love-letter worm that cost $10 billion — how malware learned to lie, seduce, and outrun the world between…
By Jijo Shibu
12 min read
Cybersecurity Origins · Part 2
From shape-shifting viruses to a love-letter worm that cost $10 billion — how malware learned to lie, seduce, and outrun the world between 1990 and 2004.
This is Part 2 of the series Malware Programs in Computer History. In Part 1 → we followed malware's first two decades — from Creeper's playful 1971 note to the world's first ransomware arriving by post in 1989. This part picks up in 1990, exactly where that story left off. If you're new here, start with Part 1 — everything below builds on it.
On May 4, 2000, millions of people opened their inbox and found the same three words waiting: ILOVEYOU.
It came from someone they knew. It promised a love letter. Within 24 hours it had torn through banks, parliaments, and the Pentagon, and would go on to cause an estimated $10 billion in damage. And it worked for one simple reason: by the year 2000, malware had stopped picking locks — and started knocking politely on the front door.
If Part 1 was the story of malware being born, this is the story of malware being raised — the fourteen years between 1990 and 2004 when it went to school and learned the oldest trade in the world.
I think of this whole era through one frame: malware learned the con artist's playbook. A good con artist never forces anything. He works with four tools — disguise (he never looks the same twice), credibility (he arrives on official letterhead), seduction (he tells you exactly what you want to hear), and speed (he's gone before you know what happened). Between 1990 and 2004, malware picked up those four tools one at a time, in almost that order. Let's watch it happen.
Era 1: Masters of Disguise (1990–1995)
Malware #11–1260 (1990). By 1990, antivirus had a working strategy: recognise each virus by its signature — a unique snippet of code, like a fingerprint on file. Then Mark Washburn wrote 1260, one of the first polymorphic viruses: it rewrote its own code with every infection while keeping the same behaviour. Same con man, new face at every hotel. Overnight, the entire fingerprint-matching approach had a hole in it — and the industry has been chasing shape-shifters ever since.
Malware #12 — Michelangelo (1991). A boot sector virus rigged to overwrite disks every March 6, the artist's birthday. Technically ordinary. Culturally, a landmark: in early 1992 experts warned that millions of machines would be wiped, TV news ran countdowns, and antivirus flew off the shelves. March 6 arrived… and confirmed damage was in the low thousands. Michelangelo taught two lessons at once — malware could manufacture mass public panic, and fear could be more profitable than any payload. Keep that in mind next time a "digital doomsday" headline crosses your feed.
Malware #13 — Concept (1995). For 25 years one rule held: programs can be infected, documents are safe. Concept broke it. It was the first widespread macro virus — malicious code hiding inside a Microsoft Word document's automation features, infecting Word itself the moment the file opened. The con artist had learned to forge letterhead: the attack now travelled inside the most trusted, most-shared file type in every office on Earth. Within a year, macro viruses were the most common malware in the world.
📖 Key Terms Signature detection — Spotting malware by matching known snippets of its code. Polymorphic virus — Malware that rewrites its own code at every infection to slip past signatures. Macro — A mini-program embedded in a document to automate tasks — here, abused to attack. Boot sector virus — A virus that loads from the first thing a computer reads at startup (see Part 1).
So documents were now weapons, and disguises were perfected. But everything up to here only destroyed data. What if a virus could destroy the machine itself?
Era 2: Playing With Fire (1998–1999)
Malware #14 — CIH, a.k.a. Chernobyl (1998). Written by Taiwanese student Chen Ing-hau, CIH crossed a line no major malware had crossed. On April 26 — by grim coincidence, the Chernobyl anniversary — it overwrote the start of the hard drive and tried to flash-erase the BIOS, the chip that teaches a computer how to switch on. Victims didn't get an error message; they got a machine that would never boot again. Hundreds of thousands of PCs, mostly across Asia, were effectively bricked. The con artist had graduated to arson: not robbing the building — burning it down.
Malware #15 — Melissa (1999). Then came the move that still shapes email security today. David L. Smith released a Word document that, once opened, used Outlook to email itself to the first 50 people in your address book — arriving, crucially, from you. Your colleagues trusted it because they trusted you. Melissa spread so fast that Microsoft and others shut their email systems down to contain it. This was the masterstroke: impersonation. Why forge credibility when you can borrow your victim's?
📖 Key Terms BIOS / firmware — Low-level code on a chip that starts the computer before any operating system loads. Mass-mailer worm — Malware that spreads by emailing copies of itself to a victim's contacts. Social engineering — Hacking people rather than machines: exploiting trust, curiosity, and habit.
💡 Think about it this way: Melissa didn't exploit a flaw in Outlook. It exploited a flaw in us — the reflex to open anything a friend sends. There's no patch for that.
Melissa reached the first 50 contacts per victim. What happens when you take the same trick and attach the single most irresistible subject line in human history?
Era 3: The Love Letter Years (2000–2001)
Malware #16 — ILOVEYOU (2000). A 24-year-old in Manila, Onel de Guzman, reached for the con artist's ultimate weapon: seduction. The subject said ILOVEYOU; the attachment was "LOVE-LETTER-FOR-YOU.TXT.vbs" — a script wearing a text file's name as a mask. Open it and it overwrote your files and mailed itself to everyone in your address book, not just fifty. It circled the planet in hours, hit an estimated one in ten internet-connected PCs, and forced institutions from the UK Parliament to the Pentagon offline. The twist: the Philippines had no law against writing malware in 2000, so de Guzman walked free — and the country wrote its first cybercrime statute in direct response. One email, ten billion dollars, one new law. That's leverage.
Malware #17 — Code Red (2001). While the world obsessed over email, Code Red skipped humans entirely. It attacked web servers through a flaw in Microsoft's IIS software, spreading machine-to-machine with no clicks and no attachment — and, remarkably, no file on disk: it lived purely in server memory. Infected sites were defaced with "Hacked By Chinese!", and the worm aimed a coordinated flood at the White House website, which had to change its address to dodge it. Roughly 359,000 servers fell in under 14 hours. The con artist no longer needed to fool anyone — the buildings themselves had unlocked windows.
📖 Key Terms VBS script — A small Windows program written in Visual Basic; ILOVEYOU's true form. Double-extension trick — Naming a file "photo.jpg.exe" so the dangerous ending stays hidden. Buffer overflow — Overstuffing a program's memory until your own code spills in and runs. Fileless / memory-resident malware — Malware that lives only in RAM, leaving no file to scan. DDoS — Flooding a target with traffic from many machines until it collapses.
Code Red took a third of a million servers in half a day, and that felt like the ceiling. It wasn't. The next worm would do its damage in ten minutes.
Era 4: Need for Speed (2003–2004)
Malware #18 — SQL Slammer (2003). The most breathtaking entry on this list is also the smallest: 376 bytes — shorter than this paragraph. Slammer fit inside a single network packet aimed at Microsoft SQL servers. No file, no email, no payload — it did nothing but spread, doubling its infected population roughly every 8.5 seconds. Within about 10 minutes it had hit ~75,000 servers, and the raw traffic knocked out Bank of America ATMs, airline check-in desks, and much of South Korea's internet. Slammer proved a humbling law of the connected city: you don't need a bomb to cause a blackout. Congestion is a weapon.
Malware #19 — MyDoom (2004). Then the professionals arrived. MyDoom is still, by most estimates, the fastest-spreading email worm ever — at its peak a meaningful fraction of all email on Earth was MyDoom. But look at what it did: it opened backdoors on infected machines and aimed a DDoS cannon at a specific company. This wasn't a prank or a love letter — it was infrastructure-for-hire, treating infected PCs as an asset. Its author was never identified. The con-artist era was ending; the age of organised, profit-driven cybercrime — botnets, spam empires, and eventually the ransomware gangs of today — begins right here.
Malware #20 — Cabir (2004). And the list closes with a quiet, prophetic beep. Cabir was a proof-of-concept worm for Symbian phones that spread over Bluetooth, hopping between handsets in the same room, flashing "Caribe" and draining batteries as it endlessly hunted for new victims. Harmless — and historic. For 33 years malware had lived in buildings: labs, offices, server rooms. Cabir followed us out the door and into our pockets. Every strain of mobile spyware and banking malware today is Cabir's descendant.
📖 Key Terms Botnet — A network of infected machines controlled remotely as one group. Backdoor — A hidden entrance left behind so the attacker can return later. Proof of concept — Code written to prove an attack is possible, not to cause harm.
How a Mass-Mailer Worm Works, Step by Step
Melissa and ILOVEYOU — the two defining outbreaks of this era — both ran the same five-step con:
Step 1: The lure. An email arrives from someone you know, with an irresistible subject — a report, a love letter.
Step 2: The mask. The attachment hides its real nature — a script dressed up as a harmless text file or Word doc.
Step 3: The click. You open it. The code runs with your permissions, as if you'd typed it yourself.
Step 4: The harvest. It reads your address book — your entire web of trust — in under a second.
Step 5: The relay. It mails itself to your contacts, signed by you, and the loop restarts at Step 1 — now multiplied by everyone you know.
Think of it like a chain letter that writes itself, forges your signature, and licks its own stamps.
Why It Matters
Almost every security habit you're nagged about today was written in this era's blood. Blocked attachments and file-type warnings? Melissa and ILOVEYOU. "Patch Tuesday" and automatic updates? Code Red and Slammer — both exploited flaws that already had fixes available that nobody had installed. Skepticism toward scary headlines? Michelangelo. Behaviour-based antivirus instead of pure signatures? 1260's shape-shifting made it inevitable.
And the deepest shift: somewhere between Melissa and MyDoom, the target of attack moved from computers to people and profit. That shift never reversed. Modern phishing, business email compromise, and ransomware are all direct descendants of the con artist's playbook this era perfected — which is exactly where Part 3 of this series will pick up.
Common Misconceptions
- "Only .exe program files are dangerous." Concept hid in Word documents; ILOVEYOU was a script wearing a .TXT mask. The file type you see is not the file type you get.
- "Big attacks need sophisticated code." SQL Slammer was 376 bytes with no payload at all — raw speed did every bit of the damage.
- "Media panic tells you whether a threat is real." Michelangelo cuts both ways: the doomsday never came, but the virus was genuine. Calibrate — don't dismiss, and don't buy the countdown clock either.
Key Takeaways
- 1260 (1990) turned viruses into shape-shifters, breaking signature-only antivirus for good.
- Concept (1995) proved documents could attack — the office's most trusted file became its most dangerous.
- CIH (1998) showed malware could destroy hardware, not just data, by burning the BIOS.
- Melissa (1999) and ILOVEYOU (2000) weaponised trust itself: attacks now arrived from your friends.
- Code Red (2001) and SQL Slammer (2003) removed humans from the loop — fileless, click-less, measured in minutes.
- MyDoom (2004) marked the arrival of organised, profit-driven cybercrime; Cabir (2004) carried malware into our pockets.
⚠️ Going Deeper
If the basics clicked and you want to go further, here's what to explore next:
- Anna Kournikova worm (2001) — built with a point-and-click worm toolkit, foreshadowing today's malware-as-a-service.
- Blaster & Sasser (2003–2004) — the network worms that forced Microsoft's security overhaul in Windows XP SP2.
- Polymorphic vs metamorphic malware — how 1260's disguise trick evolved from re-encrypting code to fully rewriting it.
- Fileless malware today — Code Red and Slammer were the ancestors of the memory-only attacks that dominate modern breaches.
- Zeus (2007) and Conficker (2008) — the banking-theft and mega-botnet era MyDoom pointed toward (and the opening act of Part 3).
🧠 Quick Knowledge Check
Try answering these before scrolling to the answer key — you'll be surprised how much stuck!
- What made the 1260 virus historically important, and which detection method did it defeat?
- Why is Michelangelo remembered more for its media coverage than its damage?
- What long-standing assumption did the Concept virus destroy in 1995?
- What did CIH do that no major malware had done before, and on which date did it trigger?
- How did Melissa choose its next victims, and why did that make it so believable?
- Name two deception tricks ILOVEYOU packed into a single email.
- What legal loophole let ILOVEYOU's author walk free, and what changed because of it?
- How were Code Red and SQL Slammer fundamentally different from Melissa-style worms?
- Why does MyDoom mark a turning point in who writes malware and why?
- 🔍 Research question: Onel de Guzman stayed silent for 20 years. In 2020 a journalist finally tracked him down and got a confession. What was his stated motive for writing ILOVEYOU — and what was he doing for a living when he was found?
📖 Answer Key
No peeking before you've tried! Answers are here to confirm, not replace, your thinking.
Q1: It was one of the first polymorphic viruses — it rewrote its own code at every infection, defeating signature-based antivirus detection.
Q2: Experts and TV news predicted millions of wiped machines on March 6, 1992; confirmed damage was only in the low thousands. It became the textbook case of cyber-doomsday hype.
Q3: That documents are passive and safe. Concept was the first widespread macro virus, hiding executable code inside Word files — the world's most-shared "harmless" format.
Q4: It attacked hardware — overwriting the drive's start and flash-erasing the BIOS, leaving machines unbootable. It triggered on April 26, coincidentally the Chernobyl anniversary, hence the nickname.
Q5: It emailed itself to the first 50 contacts in the victim's Outlook address book, so every copy arrived from a real, trusted sender.
Q6: An irresistible subject line ("ILOVEYOU") preying on curiosity, and the double-extension mask ("…TXT.vbs") making a script look like a plain text file. (Arriving from a known contact counts too.)
Q7: The Philippines had no law criminalising malware in 2000, so he couldn't be prosecuted; the country passed its first e-commerce/cybercrime law shortly after, directly because of the outbreak.
Q8: They attacked servers directly through software flaws — no email, no attachment, no human click, and largely no file on disk. Humans were removed from the infection loop entirely.
Q9: It wasn't a prank: it built backdoors and launched a targeted DDoS, treating infected PCs as a criminal asset — signalling the shift from hobbyist authors to organised, profit-driven cybercrime.
Q10: He told journalist Geoff White he wrote it partly to steal internet-access passwords because he couldn't afford to get online — and when found in 2020 he was running a small mobile-phone repair stall in Manila.
In Part 1, malware announced itself and asked to be caught. In this era it learned to wear your best friend's face, fit inside a single packet, and follow you out the door in your pocket. The con artist's four tools — disguise, credibility, seduction, speed — were now complete. Everything that comes next is the same playbook… with a business model bolted on.
Coming Next in the Series
Part 2 ends in 2004, the moment malware becomes a business. Part 3 — The Malware That Turned Pro — follows the money: the silent banking trojan Zeus that emptied accounts without a trace, the Conficker botnet that enslaved millions of machines and baffled the world, and Stuxnet, the first piece of code built to physically destroy real-world machinery. The pranks are over. The professionals — and the nation-states — have arrived.
👉 Missed the start? Read Part 1: The First 10 Malware Programs in Computer History →
The series runs chronologically from 1971 to the modern ransomware era — follow along so you don't miss the next installment.
If you found this useful, give it a clap 👏 — it helps more people discover it. And if you have questions, drop them in the comments. I read every one.
Want to talk cybersecurity, share resources, or just connect? Find me on LinkedIn — I'm always happy to connect with curious minds.