Delaware. Like Joe Dellinger at A&M, who was surprised at how quickly his self-replicating programs had traveled, Basit and Amjad Alvi were startled that their little virus had emigrated all the way to America in less than a year. The second documented virus attack occurred only a month later, in November 1987, on computers at Lehigh University in Bethlehem, Pennsylvania. Unlike Brain, the virus at Lehigh was deliberately damaging. It kept a count of the number of files that it infected and, when its counter reached four, it trashed the diskette by overwriting it with "garbage" collected from another part of the computer. The university's senior computer consultant, Ken van Wyk, realized he had a problem when students began complaining that their diskettes didn't work. At first there was a trickle of bad diskettes, then a flood. Something was zeroing out the diskettes, and Van Wyk guessed that it was probably a virus. Van Wyk worked for five days to isolate the bug and find a cure. He discovered that, unlike Brain, the Lehigh virus did not infect the boot sector; instead, it hid itself inside one of the three start-up programs that are triggered immediately after the boot had occurred. Like Brain, the virus jumped into memory whenever a computer was started from an infected diskette. Van Wyk also discovered that the antidote was extremely simple: all he needed to do was delete the infected start-up program and replace it with a clean one. The data on the trashed diskettes, however, was irrecoverable. Van Wyk notified colleagues at other colleges that the virus "is not a joke. A large percentage of our disks have been gonged by this virus in the last couple of days." Later that year the university suffered another attack from a modified version of the same virus. This one trashed a diskette after infecting ten files, as opposed to four. The longer delay made the new version of what was by then known as the Lehigh virus much more insidious in that it infected more diskettes with versions of itself, and therefore propagated more widely, before unleashing its payload. But because the antidote was already known to Van Wyk, the cleanup operation was quick. The writer of the Lehigh virus was never discovered, though he or she was assumed to be a student at the university. But by one of those concurrences that excite conspiracy theorists, the professor of electrical engineering and computer science at Lehigh when the viruses attacked was Fred Cohen, by then Dr. Cohen, the same student who two years earlier had written the dissertation that had first coined the term computer virus. Early in 1988 two more viruses were discovered, both of them written for the Macintosh, a personal computer produced by Apple, which had become the successor to its historic Apple II. The first became known as MacMag or, sometimes, Peace, and contained the phrase "universal message of peace" signed by Richard Brandow, the publisher of MacMag Magazine, a Canadian publication for Macintosh users. It also included a small drawing of the world autographed by the author of the virus, Drew Davidson. Later it was discovered that the virus had been included on a computer game shown at a meeting of a Macintosh users' group in Montreal. A speaker at the meeting had accidentally copied the virus onto a diskette, and subsequently infected a computer in the offices of Aldus, a Seattle-based software publisher, for whom he was doing some work. The company then unwittingly copied the virus onto what was later described as "several thousand" copies of a program called Freehand, which were distributed to thousands of computer stores. After complaints from consumers, who were quite bewildered at receiving a peace message with their software, the company recalled five thousand copies of the program. The MacMag virus, though relatively widely distributed, was not malicious. After displaying its message, it removed itself from infected systems. Nevertheless, it was an unwanted extra and served to demonstrate the speed and ease with which self-replicating programs could propagate. When questioned about the morality of deliberately publishing Davidson's virus, Brandow was quoted as saying, "You can't blame Einstein for Hiroshima." The second Macintosh virus to be reported in 1988 was called Scores and was much more serious. On April 19,1988 Electronic Data Systems (EDS) of Dallas, a subsidiary of General Motors, announced that twenty-four of its machines had been infected with a virus that was thought to have been written by a disgrun- tled ex-employee. The virus had infected the operating system and two standard files of each computer, and then hidden itself inside two more secret files that it had created. Two days after a system has been infected with Scores, the virus begins to spread to the other programs on the computer--in particular, it looks for two specific programs developed by EDS, and when it finds them, it prevents the computer user from saving his data, thereby causing the loss of whatever he was workin~ on. By early 1988 a small but potentially lucrative computer security industry had begun to specialize in protecting machines from viruses. A number of computer specialists offered their services as security consultants or sold computer software designed to track down and kill viruses. But despite Brain, Lehigh, and the two Macintosh viruses, there was little real evidence of the oft-hyped plague of computer bugs. It was understandable that writers of antiviral software and others in the new security industry would exaggerate the threat; they were like burglar-alarm salesmen in a community without very many burglars. They needed to convince the public that a slew of viruses was gathering, to be unleashed on defenseless computer users in the coming year. The emotive term virus helped their case, as did the willingness of the press to publish dubious statistics and unverified, unsourced stories of virus incidents--particularly the computer magazines, which were then locked in a difficult circulation war and looking for something out of the ordinary to write about. Viruses made good copy, as did nightmarish stories about the effects of a plague. In essence, the burglars hadn't quite hit town yet, but by God they were on the way. One of the earliest antiviral programs for IBM PC-type computers was the work of a New York-based programmer, Ross Greenberg. He said that he had seen the impending virus threat coming for years, and had therefore created a program called Flu Shot. During the summer of 1988 Greenberg was contacted by writer Ralph Roberts, who was researching a book about computer viruses. According to Roberts, Greenberg insisted that he had "about twenty viruses in quarantine." When asked to identify them, Greenberg told the writer, "I don't give the little suckers names." But he did describe his "favorite virus," which he said could randomly transpose two numbers on the screen. "Sounds cute," he reportedly said, "but it could be dangerous if you're using Lotus 1-2-3 [a program used for accounting] to run a multimillion-dollar company." Roberts's book, Computer Viruses, was the first attempt to put the problem into perspective. In it he describes his interviews with t he newly formed Computer Virus Industry Association (CVIA), a body representing virus researchers and consultants that had identified "twenty different types that attack IBM PCs and compatibles" and fourteen others that infect other types of computers. The CVIA also listed the names of the top five virus strains by reported incidence as Scores, Brain, SCSI, Lehigh, and Merritt. Yet the Lehigh virus seemed to be confined to Lehigh University; Brain was relatively harmless in that the damage it caused was infrequent and accidental; and the Merritt virus (sometimes called Alameda or Yale) was a benign virus that simply replicated and had been seen at only a few universities and colleges. The SCSI virus attacked only the Amiga, which was primarily a games machine. The most threatening virus on the list was Scores, even though it seemed to be directed against one particular company. Of the twenty-nine other reported viruses, either they had been seen only once or twice or their existence was unconfirmed. (The twenty viruses Greenburg claimed to have in quarantine were not on the list.) And that, according to the CVIA, was about the size of the virus problem in the summer of 1988. In the following year Greenberg wrote an article for Byte, an 92 APPROACHING ZERO eminently respectable American computer magazine, in which he described two of the viruses he had in quarantine: his favorite number-transposing virus, now named Screen, and a similar one that he had reported to researchers as dBase, which transposed characters within files. It was called dBase because it targeted records generated by a popular program of the same name. In 1988 and even early 1989, viruses were exceedingly rare, so there was a growing suspicion about Greenberg's claims to have twenty unnamed bugs in some sort of quarantine. It was thought that Greenberg was exaggerating for effect. Other virus researchers understandably wanted copies of Greenberg's viruses and, in particular, the dBase virus he had described in detail. Eventually Greenberg produced a copy of dBase. It wasn't quite as he had first described it; it had only been seen on one unidentified site, and only then by Greenberg, but at least its existence could be verified. However, the existence of the other nineteen viruses, including Screen, has yet to be confirmed. Other early viruses were equally problematic. A virus researcher named Pamela Kane told writer Ralph Roberts about the Sunnyvale Slug, which flashed the message, "Greetings from Sunnyvale. Can you find me?" on infected machines. But it has never been confirmed as a virus, nor seen since Kane first reported it. Then there was the "retro-virus," reported to have been distributed with three popular but unnamed shareware (free, shared software) programs. It was said to have been programmed to detach itself from its infected hosts--a program or file--and then to reinfect them at some future date. It was "like a submarine rigged for silent running . . . the retro-virus waits until the destroyers have stowed their depth charges and gone back to port before returning to sink ships," it was claimed, somewhat colorfully, in the computing journal Info World At the time, the retro-virus was without a doubt the most sinister virus ever reported, but it had only been seen once--by the researcher who reported it. The CVIA was not averse to creating a few myths of its own. Its chairman, John McAfee, an ebullient and eminently quotable computer expert, was always available to fill in the press on the irresistible spread of viruses. He was a good interviewee, with a store of anecdotes about computer viruses and reports of virus attacks at generally unidentified companies and institutions, and he managed to give the impression that each anecdote could lead to a thousand more, that each incident was representative of a hundred others. In 1988 and 1989, reports about viruses always intimated that what was public knowledge was only the tip of the iceberg--that the problem was much bigger, much wider, and much more pervasive than anyone suspected. But far from being the tip of the iceberg, what had been reported was the whole problem--and even that was seen through a prism. The hype had its effect, however, and sales of antivirus software soared. Born in science fiction, legitimized by academia and institutionalized by the Computer Virus Industry Association, the computer virus finally came of age on September 26,1988, when it made the front cover of Time magazine. Time was once derided as the publication "for those that can't think" (its sister publication, Life, was said to be "for those who can't read"). It has been accused of publishing middle-brow analyses and overwrought cover stories, and its ability to be out of touch has been so noticeable that in show business the offer of a Time cover story is considered a sure sign that the unfortunate star's career is on the wane. Not that anyone has ever turned down a cover story--Time is still one of the most influential publications in America, and for better or worse, what it says is often believed. So, when Time headlined its cover about computer viruses "Invasion of the Data Snatchers!" its readers were more than certain that data was indeed being snatched. The magazine detailed an attack on a local newspaper office by the Brain virus, and called it a "deliberate act of sabotage." Brain, Time said, was "pernicious," "small but deadly," and "only one of a swarm of infectious programs that have descended on U.S. computer users 94 APPROACHING ZERO this year." The magazine also announced, "In the past nine months, an estimated 250,000 computers have been hit with similar contagions." The article captured perfectly the hyperbole about viruses: Brain was far from pernicious, and it certainly wasn't deadly. There was no swarm of viruses: the number then proven to have infected systems--as opposed to those conjured up in the imaginations of virus researchers--was probably less than ten. And as for the estimate that 250,000 computers had been hit by viruses, it was just that-- an estimate. No one at the time had any real idea how many computer sites had been affected. The Time writer also dug deep to unearth the Cookie Monster, which had appeared during the 1970s at a number of American colleges. Inspired by a character on the children's television show Sesame Street, this joke program displayed a message on a computer screen: I WANT A COOKIE. If the user typed in "cookie," it would disappear, but, if the message was ignored, it kept reappearing with increasing frequency, becoming ever more insistent. But the Cookie Monster wasn't a virus, even in the broadest definition of the term: it was a joke program introduced by a prankster on a single computer; it had no ability to replicate and it couldn't travel surreptitiously from machine to machine. Time did recognize that "the alarm caused by these . . . viruses was amplified by two groups with a vested interest in making the threat seem as dramatic as possible"--the computer security specialists and the computer press, "a collection of highly competitive weekly tabloids that have seized on the story like pit bulls, covering every outbreak with breathless copy and splashy head- lines." It was an apt description of the exaggerated coverage of the virus phenomenon. But the threat would soon become real. On the evening of November 2, 1988, a little over five weeks after the Time story appeared, events occurred that seemed to fulfill all of the doomsday prophecies. Between 5:00 and 6:00 P.M., eastern standard time, on that Wednesday ni~ht, a ro~ue pro~ram was loaded onto the ARPANET system. Three hours later, across the continent at the Rand Corporation in Santa Monica, operators noticed that their computers were running down. Something was taking up computer space and slowing the machines to a crawl. At 10:54 P-M- managers at the University of California at Berkeley discovered what they thought was a hacker trying to break into their systems. As the attempts continued and the attacks increased, they realized to their horror that it wasn't a hacker. It was a program, and it was multiplying. By that time the same program was attacking the computer at MIT's Artificial Intelligence Laboratory as well as sites at Purdue, Princeton, and Stanford. It was moving across networks, spreading from the ARPANET onto MILNET--the Department of Defense computer network--and then onto Internet, which itself links four hundred local area networks. It spread to the Lawrence Livermore National Laboratory, then to the University of Maryland, then across the country again to the University of California campus at San Diego, and then into the NASA Ames Laboratory, and the Los Alamos National Laboratory in New Mexico. Within a few hours the entire Internet system was under siege. Peter Yee, at Ames, posted the first warning on the network's electronic mail service at 2:28 A.M.: "We are currently under attack from an Internet virus. It has hit UC Berkeley, UC San Diego, Lawrence Livermore, Stanford, and NASA, Ames . . ." Yee had earlier spotted what seemed to be an entire army of intruders attempting to storm his computer. He counterattacked, killing off some of the invaders. But then came another wave, and another, and he was soon overwhelmed. His powerful computer had started to slow down noticeably, its energy drained by the proliferation of vampire programs that were reproducing uncontrollably and monopolizing its resources. The same attackers hit the MIT Media Laboratory in Massachusetts. Pascal Chesnais, a scientist who had been working late in the lab, thought he had managed to kill off his mysterious intruderS~ then went to grab a meal. When he got back, he found 96 APPROACHING ZERO that more copies of the invaders were coming in with his elec tronic mail, so he shut down his network connection for a few hours. Then, at 3:10 A.M., he sent out his own warning: ' A virus has been detected at Media Lab. We suspect that the whole Internet is infected by now. The virus is spread by [electronic] mail . . . So mail will not be accepted or delivered." Just before midnight the rogue program had spread to the Ballistic Research Laboratory, an army weapons center in Mary land. The managers at the lab feared the worst: they could be under attack from hostile agents. Even if that proved not to be the case, they didn't know what the program was doing. It was cer- tainly multiplying, that was clear, but it might also be destroying data. By the next morning the lab had disconnected itself from the network and would remain isolated for nearly a week. It wasn't alone in disconnecting--so many sites attempted to isolate themselves that electronic mail (the usual channel of communication between computer operators) was hampered, creating even more confusion about what was happening. At one point the entire MILNET system severed all mailbridges--the transfer points for electronic mail--to ARPANET. By midnight the electronic freeways between the sixty thousand or so interconnected computers on Internet and ARPANET were so clogged with traffic that computer specialists were roused from their sleep and summoned to their offfices to help fight the attack. Most of them wouldn't get back home until the next night. At 3:34 A.M. on November 3rd, shortly after Yee had sounded the first alarm, another message about the virus was sent from Harvard. This message was much more helpful: it wasn't just a warning, but offered constructive suggestions and outlined three steps that would stop the virus. The anonymous sender seemed to be well informed about its mechanisms, but because of the chaos on the network, the message wouldn't get through for forty-nine hours. At first the experts believed that all of the sixty thousand-plus computers on the besieged networks were at risk. But it quickly became apparent that the rogue program was attacking only particular models: Sun Microsystems, Series 3 machines, and VAX computers running variants of the UNIX operating system.l On infected machines unusual messages appeared in the files of some utilities, particularly the electronic-mail handling agent, called Sendmail. But what was most apparent was that the rogue program was multiplying at devastating speed, spreading from computer to computer, reinfecting machines over and over. As the reinfections multiplied, the systems became bogged down; then the machines ran out of space and crashed. On the morning of Thursday, November 3rd, Gene Spafford, a computer science professor at Purdue University, sent the following message to his colleagues: "All of our Vaxen2 and some of our Suns here were infected with the virus. The virus made repeated copies of itself as it tried to spread, and the load averages on the infected machines skyrocketed. In fact, it got to the point that some of the machines ran out of space, preventing log-in to even see what was going on!" Spafford did manage to capture part of the rogue program, but only the half that controlled its spread. The other half, the main operating system within the program, erased itself as it moved from computer to computer, so as not to leave any evidence. The deviousness of the program lent weight to the theory that it would also be damaging: that the rogue program could somehow have been tampering with systems, altering files, or destroying information. The rogue program, it was subsequently discovered, moved from computer to computer by exploiting flaws in the Berkeley version of UNIX. The principal flaw was in Sendmail, the program designed to send electronic mail between computers in the interlinked networks. A trapdoor on Sendmail would allow com- mands (as opposed to actual mail) to be sent from computer to computer. Those commands were the rogue program. Once it had entered one computer through Sendmail, it would collect information about other machines in the system to which it could jump, and then proceed to infect those machines. 98 APPROACHING ZERO In addition to exploiting the Sendmail flaw, the rogue program could try to guess the passwords to jump to target computers. Its password routine used three methods: it tried simple permuta tions of known users' names, it tried a list of 432 frequently used passwords, and it also tried names from the host computer's own dictionary.3 If one method didn't work, it would try another and then another until it had managed to prise open the door of the target computer. An early analysis of the program made at four A.M. on the morning after the initial attack described it as "high quality." Some twelve hours after its release, it was estimated that about 6,200 computers on Internet had been infected; the costs, in downtime and personnel, were mounting. In the meantime, three ad hoc response teams, at the University of California at Berkeley, at MIT, and at Purdue, were attempting to put an end to the attack. At five A.M. the Berkeley team sent out the first, interim set of instructions designed to halt the spread. By that time the initial fears that the rogue program might destroy information or systems had proved unfounded. The program, it was discovered, was designed to do nothing more than propagate. It contained no destructive elements apart from its ability to multiply and reinfect to such an extent that it would take over all available space on a target computer. Later on Thursday the team at Purdue sent out an electronic bulletin that catalogued methods to eradicate the virus. And at Berkeley they isolated the trapdoors it had used and published procedures for closing them. Once the commotion had died down and computer managers had cleared out the memories on their machines and checked all the software, their thoughts turned to the reasons for the attack. That it was deliberate was certain: the rogue program had been a cleverly engineered code that had exploited little-known flaws in UNIX; it had erased evidence of its intrusions on the computers it had infected; and it was encrypted (written in code) to make it more difficult to tear apart. There was little doubt in anyone's mind that the program was the work of a very clever virus writer, perhaps someone who had a grudge against ARPANET or one of the universities, a computer freak outside of the mainstream attempting to get back at the establishment. But these suppositions were wrong. Internet's rogue program became a media event. The New York Times called the incident "the largest assault ever on the nation's systems." The program itself became known as the Internet Virus or, more accurately, the Internet Worm.4 At a press conference at MIT the day after the worm was released onto ARPANET, the university's normally reticent computer boffins found themselves facing ten camera crews and twenty-five reporters. The press, the MIT researchers felt, was principally concerned with confirming details of either the collapse of the entire U.S. computer system or the beginning of a new world war, preferably both. One participant had nightmarish visions of a tabloid headline: COMPUTER VIRUS ESCAPES TO HUMANS, 96 KILLED. The incident received worldwide press coverage, and the extent of the damage was magnified along the way. One of the first estimates--from John McAfee, the personable chairman of CVIA--was that cleaning up the networks and fixing the system's flaws would cost $96 million. Other estimates ran as high as $186 million. These figures were widely repeated, and it wasn't until later that cooler heads began to assess the damage realistically. The initial estimate that about 6,200 machines, some 10 percent of the computers on Internet, had been infected was revised to roughly 2,000, and the cleanup cost has now been calculated at about $1 million, a figure that is based on the assumed value of "downtime," the estimated loss of income while a computer is idle. The actual restitutional cost has been assessed as $150,000; McAfee's exaggerated estimate of $96 million was dismissed. By the time the real assessments had been made, the identity of the author of the worm had been discovered. He was Robert Morris, Jr., a twenty-three-year-old graduate of Harvard University and, at the time of the incident, a postgraduate student at Cornell. Far from being an embittered hacker or an outsider, he 100 APPROACHING ZERO was very much the product of an "insider" family. His father Robert Morris, Sr., was the chief scientist at the National Computer Security Center, a nationally recognized expert on computer crime, and a veteran of Bell Laboratories. He was, coincidentally, also one of the three designers of a high-tech game called Core Wars, in which two programs engage in battle in a specially reserved area of the computer's memory. The game, which was written in the early 1960S at Bell, used "killer" programs that were designed to wipe out the defenses of the oppo nent. The curious similarities between Core Wars and the Internet Worm were often cited in press reports. Morris received an enormous amount of publicity after his identity became known. His motives have been endlessly reviewed and analysed, especially in a recent book, Cyberpunk, that was partly devoted to the Internet Worm. The consensus was that Morris wrote a program that fulfilled a number of criteria, including the ability to propagate widely, but that he vastly underestimated the speed at which it would spread and infect and then reinfect other machines. He himself called the worm "a dismal failure" and claimed that it was never intended to slow computers down or cause any of them to crash.S His intention, he said, was for the program to make a single copy on each machine and then hide within the network. When he realized, on the night of November 2nd, that his program was crashing computers on the linked networks, he asked a friend, Andrew Sudduth, to post an electronic message with an apology and instructions for killing the program. That was the message sent out at 3:34 A.M., the one overlooked in the general confusion. Morris was indicted for "intentionally and without authorization" accessing "federal-interest computers," preventing their use and causing a loss of at least $1,000 (that figure being the minimum loss for an indictment). The charge, under a section of the 1986 Computer Fraud and Abuse Act, potentially carries a fine of $250,000 and up to five years in prison. Morris was tried in January 1990. HiS defense lawyers said that be had been attempting to "help security" on Internet and that his program had simply gotten out of control. The prosecution argued that "the worm was not merely a mistake; it was a crime against the government of the United States." On January 22nd a federal jury found Morris guilty, the first conviction under that particular section of the 1986 act. Despite the verdict the judge stated that he believed the sentencing requirements did not apply in Morris's case, saying the circumstances did not exhibit "fraud and deceit." The sentence given was three years' probation, a fine of $10,000, and four hundred hours' community service. The type of program that Morris had released onto ARPANET, a worm, has been defined as a program that takes up residence in a computer's memory, similar to the way a real worm takes up residence in an apple. Like the biological worm, the electronic one reproduces itself; unlike the real-life worm, however, the offspring of a computer worm will live in another machine and generally remain in communication with its progenitor. Its function is to use up space on the computer system and cause the machine to slow down or crash. To researchers there is a clear distinction between worms and viruses, which are a separate sort of malicious program that require a "host," a program or file on a disk or diskette that they can attach themselves to. Viruses almost always have a payload as well, which is designed to change, modify, or even attack the system they take residence on. Worms can also usually be destroyed by closing down the network. The fact that worms can travel independently from one linked machine to another has always intrigued programmers, and there have been many attempts to harness this ability for beneficial purposes. Ironically, one of the first experiments was made on ARPANET. A demonstration program called Creeper was designed to find and print a file on one computer, then move to a second and repeat the task. A later version not only moved 102 APPROACHIN~ ZERO through computers performing chores, but could also reproduce, creating perfect clones of itself that would undertake the same chores and replicate again. The problem became obvious: the number of worms would increase exponentially as each generation replicated, creating a seemingly endless number of clones. The solution was to create another, nonreplicating worm, called the Reaper, which would crawl through the system behind the Creeper and kill off the proliferating clones after they had performed their tasks. The experiment was abandoned when it became apparent that the Reaper would never be able to keep up with the proliferating number of Creepers. There are other sorts of malicious programs, including what are known as trojans--after the Greek wooden horse. The first trojan incident was reported in Germany in 1987. On the afternoon of December 9th, several students at the University of Clausthal-Zellerfeld, just south of Hannover, logged in to their computers and found that they had received electronic mail in the form of a file called Christmas. On reading the file, they saw the message LET THIS EXEC RUN AND ENJOY YOURSELF! followed by a small drawing of a Christmas tree, crudely represented by asterisks. An "exec" is an executable file, or program, and the suggestion was that if they ran the program, a large Christmas tree would appear on their computer screens. By the side of the small drawing was the greeting: A VERY MERRY CHRISTMAS AND BEST WISHES FOR THE NEXT YEAR. Underneath the drawing was a further message, in broken English: BROWSING THIS FILE IS NO FUN AT ALL JUST TYPE "CHRISTMAS," followed by some seventy lines of computer instructions. The students could recognize that these instructions were written in an easy-to-use programming language that was available on their IBM mainframe, but few could comprehend what the program was designed to do. Most of the students decided to give the program a try, typed in "Christmas," and were duly rewarded with a large drawing of a Christmas tree. Typically, they then deleted the file. However the next time they logged in to their computers, they found that they had received more copies of the Christmas file, as had many other computer users at the university. What no one had realized was that as well as drawing a Christmas tree, the program had been reading the files containing ~the students' electronic address books with the details of their other regular contacts on the IBM mainframe computer. The program then sent a copy of itself to all the other names that it could find. It was an electronic chain letter: each time the program was run, it could trigger fifty, or a hundred, or even more copies of itself, depending on the size of each user's electronic address book. The unidentified student who playfully introduced the Christmas file into the electronic mail system had probably visualized a little local fun. He hadn't realized that some of the university's computer users had electronic addresses outside Clausthal-Zellerfeld linked by EARNet, the European Academic Research Network. Or that when copies of the file started whizzing around EARNet, they would then find their way onto BitNet, an academic computer network linking 1,300 sites in the United States, and from there onto VNet, IBM's private worldwide electronic mail network, which links about four thousand mainframe computers and many more smaller computers and workstations. The electronic chain letter reached VNet on December 15th, just six days after it was launched. IBM's corporate users typically carry more names and addresses in their files than university users. Soon thousands of copies of the file were circulating around the world; it quickly reached Japan, which, like all the addresses, was only seconds . away by electronic mail. Within two days the rampaging programs brought IBM's entire network to a standstill, simply by sending Christmas greetings throughout the network. The company spent an unfestive Christmas season killing all copies of the file. The program was later dubbed the IBM Christmas Tree Virus, but because it needed some user interaction--in this case, typing in the word Christmas--it isn't considered a true virus. User interactiOn implies inviting the intruder in behind your defenses, 104 APPROACHING ZERO as the Trojans did with the Greek horse. But virus researchers have created a subcategory for trojans that replicate--as the IBM Christmas Tree did called, naturally enough, replicating trojans. The pervasive media coverage of the Internet Worm was probably one reason for the next major computer incident that year. On December 23, 1988, just six weeks after Morris's Internet Worm hit the front pages, a very different worm hit the NASA Space Physics Astronomy Network (SPAN) and the Department of Energy computer networks. Like the IBM Christmas Tree Trojan, it carried a Christmas greeting, and like the Internet Worm, it also targeted Digital Equipment's VAX computers. What later became known as the Father Christmas Worm waited until midnight on December 24th before delivering its message to users on the network: HI HOW ARE YOU? I HAD A HARD TIME PREPARING ALL THE PRESENTS. IT ISNT QUITE AN EASY JOB. IM GETTING MORE AND MORE LETTERS.... NOW STOP COMPUTING AND HAVE A GOOD TIME AT HOME!! MERRY CHRISTMAS AND A HAPPY NEW YEAR. YOUR FATHER CHRISTMAS. The Father Christmas Worm was considered nothing more than a nuisance, and did no damage. But in October 1989 the SPAN network was hit again, with a worm delivering a protest message. The new worm was a variant of Father Christmas, but this time when users logged in to their systems, they found that their normal opening page had been replaced with a large graphics display woven around the word WANK6 In ordinary characters, the symbolism was explained: WORMS AGAINST NUCLEAR KILLERS Your System Has Been Officially WANKed. You talk of times of peace for all, and then prepare for war. The arrival of the worm coincided with reports of protestors in Florida attempting to disrupt the launch of a nuclear-powered shuttle payload. It is assumed that the worm was also a protest against the launch. The WANK Worm spread itself at a more leisurely rate than the lntcrnet Worm, sending out fewer alarms and creating less hysteria. But when Kevin Obermann, a computer technician at Lawrence Livermore Laboratories, took it apart, he reported, "This is a mean bug to kill and could have done a lot of damage." The WANK Worm had some features that were not present in thc l ather Christmas Worm: to a limited extent it could evolve an(l miltate, allowing it to become just a little bit smarter as it made its way from machine to machine. In other words, the worm had bccn designed to mutate deliberately, to add to the problems that might be caused by accidental mutation or by unintentional programming errors. And, by not immediately announcing its resence, it had more time to spread. A method for combatting the worm was developed by Bernard Perrot of the Institut de Physique Nucleaire at Orsay, France. Perrot's scheme was to create a booby-trapped file of the type that the worm could be expected to attack. If the worm tried to use iformation from the file, it would itself come under attack and be blown up and killed. BY the end of 1989 the prophecies of the computer virus experts | seemed to have come true. Now not only were there viruses, but ~here was a whole panoply of malicious software to deal with: worms, trojans, and the programs known as logic bombs. Bombs are always deliberately damaging but, unlike viruses, lon't replicate. They are designed to lay dormant within a com~uter for a period of time, then explode at some preprogrammed date or event.7 Their targets vary: some delete or modify files, some ,ap the hard disk; some even release a virus or a worm when they cxplode. Their only common feature is the single blast of intentional destruction. What had started out as simple self-replicating programs had grown into a full-blown threat to computer security. Those who 106 APPROACHING ZERO had warned about the potential danger for the past two years were entitled to say, "I told you so." But the prophecies were self-fulfilling. The choice of the terrn virus to describe quite unremarkable programs glamorized the mundane; the relentless promotion of the presumed threat put ideas in the minds of potential virus writers; the publicity given the concept ensured that the writer's progeny would become known and discussed. Even if the writer himself remained anony- mous, he would know that his creative offspring would become famous. The computer underworld is populated with young men (and almost no women), mostly single, who live out their fantasies of power and glory on a keyboard. That some young men find computing a substitute for sexual activity is probably incontrovertible. Just as a handle will often hide a shy and frightened fifteen-year-old, an obsession with computing to the exclusion of all else may represent security for a sexually insecure youngster. The computer is his partner, his handle is his alter ego, and the virus he writes is the child of this alter ego and his partner. A German virus writer once said, "You feel something wonderful has happened when you've produced one. You've created something that lives. You don't know where it will go or what it will do, but you know it will live on." The antivirus industry, of course, had no thoughts of creating a hobby for insecure technology wizards when it began its campaign of publicity and hype in 1987 and 1988. But there was little question that by the end of 1989 a real threat to computer systems had been created, posed by what was indeed becoming a plague of viruses. The number of catalogued viruses in the West would grow exponentially: from thirty-odd in mid-1988, to a hundred at the end of 1989, five hundred in 1990 and over two thousand-plus at the end of 1992. Along the way the antivirus industry would lose all control of the plague--its security software overwhelmed, its confidence battered by the sheer number of new viruses confronting it. And the new viruses became much more destructive, malicious, and uncontrollable than anyone had ever imagined. Chapter 5 THE BULGARIAN THREAT In March 1990 the first attempt was made to quantify the extent of the threat posed by computer viruses. Dr. Peter Tippett, a Case Western University scholar and the president of Certus International, a software company, predicted that 8 percent of all PCs would be infected within two years, even if no new viruses were written. He estimated the cost of removing the infections at $1.5 billion over five years--not taking into account the value of the data that would be destroyed. In 1991 he estimated that organizations in North America with over four hundred computers had a 26 percent probability of being hit by a virus within the next year; they also had a 5 percent chance of that virus causing a "disaster," which he defined as an infection that spread to twenty-five or more machines. A more recent projection, made in late 1991, went farther. It suggested that as many as 12 million of the world's 70 million computers--or roughly 17 percent--would be infected within the next two years. But predictions such as those made by Dr. Tippett have proved difficult to substantiate: most virus attacks simply aren't reported; there is no body that regularly collects reliable statistics about the virus problem, and estimates of costs are always just guesses. When Dr. Tippett made his predictions, the number of new viruses that were appearing made it seem possible that their sheer volume would overwhelm the world's computer systems. By 1992, 108 APPROACHING ZERO there were over 1,500 catalogued viruses and variants in the West by spring 1993, there could well be twice that number. Tippett had based his predictions on the behavior of just one virus, called Jerusalem. It was first discovered in December 1987 at the Hebrew University in Jerusalem, though it is thought to have been written in Haifa, the country's principal port and the home of its leading technical college, Technion University. At least, that is one theory. No one has proved that the virus was written in Haifa, nor has anyone ever claimed authorship. The Jerusalem virus was a malicious joke, which would delete any program files used on Friday the 13th. There are two Friday the 13ths in any given year; in between those dates the virus signaled its presence by displaying a little box in the lower half of the computer screen and then slowing down infected systems to an unacceptable crawl. It also contained a gremlin that, contrary to the programmer's intentions, caused it to reinfect--or add itself to--many of the same program files. Eventually the files would grow so big that the virus would take up all of the computer's memory. The virus quickly acquired a fearsome reputation. Maariv, one of Israel's leading daily newspapers, heralded its discovery with an article on January 8, 1988, that warned, "Don't use your computer on Friday the 13th of May this year! On this day, the Israeli virus which is running wild will wake up from its hibernation and destroy any information found in the computer memory or on the disks." The report was somewhat exaggerated. It wasn't true that Jerusalem could destroy "any information found in the computer memory or on the disks," as it had been written to delete only programs that were used on Friday the 1 3th. In practice, few users suffered any real damage. Most operators would delete the virus as soon as they saw the little box appear on the screen and noticed the system slow down--which generally happened about half an hour after the virus had infected a computer. While Jerusalem mav not have been as destructive as its publicity suggested, it was exceptionally virulent and spread quickly and widely. Unlike most previous viruses, Jerusalem could infect nearly any common program file, which gave it more opportunity to travel. (By contrast, the Pakistani virus, Brain, could only infect the boot sector on specific diskettes, and Lehigh could only infect one particular type of program file.) Jerusalem's propagation rate was phenomenal. From Israel it spread quickly to Europe and North America, and a year after its discovery in Israel it had become the most common virus in the world. In 1989 it was said to have been responsible for almost 90 percent of all reported incidents of viral infection in the United States. Because Tippett's predictions were based on the propagation .rate of this particularly infectious bug, they probably overstated ~the potential growth rate of viruses.' One of the peculiarities of ~viruses that Tippett overlooked is that most remain localized, causing infection on a limited number of machines, sometimes on ~just a single site. So far only about fifty viruses have propagated ~rapidly and spread from their spawning ground to computers throughout the world. The rate of propagation seems to be a matter of luck. Through an unpredictable combination of circumstance and chance, some viruses are destined to wither away in parochial isolation, while others achieve a sort of international notoriety. There seems little logic to which remain localized and which propagate. In March 1989 a new virus was discovered in the United States, which was reported to have come to North America via Venezuela. Its payload was simple: it displayed the words Den and Zuk, converging from separate sides of the computer screen. The word Zuk was followed by a globe resembling the AT&T corporate k logo. Inevitably, the virus became known as Den Zuk. The bug was found to be relatively harmless. Like Brain, it nestled in the boot sector of infected diskettes, but changed their volume labels to "Y.C.I.E.R.P." Its payload was set to trigger after what is known as a warm reboot--restarting the computer 110 APPROACHING ZERO from the keyboard without using the power switch. Warm reboots are generally employed when the computer has frozen, or stopped--a fairly uncommon occurrence, so the payload wasnt triggered very often. An Icelandic virus researcher, Fridrik Skulason, surmised that the character string "Y.C.I.E.R.P" could be an amateur radio call sign. He looked up the sign in the International Callbook and found that it was attributed to an operator in Bandung, a city on the island of Java, in Indonesia. Skulason wrote to the operator, Denny Ramdhani, who replied with a long and detailed letter. He was, he admitted, the author of Den Zuk: "Den" was an allusion to his first name; "Zuk" came from his nickname, Zuko, after Danny Zuko, the character played by John Travolta in the film Grease. He had written the virus in March 1988, when he was twenty-four, "as an experiment." He wanted, he said, "to 'say hello' to other computer users in my city. I never thought or expected it to spread nationwide and then worldwide. I was really surprised when my virus attacked the U.S.A." If Denny was surprised, the computer industry was flabbergasted. Den Zuk was neither a particularly infectious bug, nor was it grown in a locale that could be said to be within the communication mainstream. Bandung, for all of its exotic charm, is not a city normally associated with high-technology industries. Denny's virus traveled simply because it got lucky. Viruses are unguided missiles, so it seems almost as likely that a bug launched from an obscure Indonesian city will hit targets in North America as one set off from, say, Germany. Nor is the sophistication of the bug any arbiter of its reach: Den Zuk was a simple virus, without any real pretension to what is known as an infection strategy. The universality of the PC culture is reflected by the provenance of viruses. In Britain, New Scotland Yard's Computer Crime Unit recently compiled a list of the country's most troublesome bugs, which originated in places as diverse as New Zealand, Taiwan. Italy, Israel (the Jerusalem virus), Austria, Pakistan (Brain), Switzerland, India, and Spain--as well as a couple from the United States and even one that is believed to be from China.2 The increasing links between virus writers in different parts of the world is demonstrated by the growing number of adaptations of existing viruses. The Vienna virus, which Ralph Burger had included in his Das grosse Computerirenbuch spawned a whole series of knockoffs, with slightly differing payloads and messages. As did the Jerusalem virus: there are now perhaps a hundred variants, all based on the one prototype. The knockoffs come from all over the world: Australia, the Netherlands, the republics of the former Soviet Union, Britain, South Africa, Czechoslovakia, Malaysia, Argentina, Spain, Switzerland, the United States--the list is only slightly shorter than the membership of the U.N. Some of the new variants are just jokes, and play tunes, but others are even more destructive than the original. Jerusalem's most fearsome variant came from Asia. Called Invader, this bug first appeared in Taiwan in July 1990, where it is presumed to have been written. Within a month it had swept through the Far East and was reported to have reached North America. Just four months later it was found at the Canadian Computer Show, where it was running amok on the PC displays. Invader is an exceptionally sophisticated variant. It would infect a target computer's hard disk, diskettes, and program files, and its payload was devastating: it would zap data stored on a hard disk or diskette to the sound of an exploding bomb whenever a particular, quite common, piece of drafting software, called Autocad, was loaded. Invader is part of the new generation of viruses: destructive, malicious, and clever. Since 1988, as the number of bugs has grown exponentially, virus techniques have improved dramatically, and their infection strategies have become more effective, which means they have a better chance of traveling. They exploit obscure functions of computers in order to evade detection; they can trash data; and in some cases, they can zero out large-scale computer networks. 112 APPROACHING ZERO While the early viruses could cause damage, it was generally by accident; the new strains are programmed to be destructive. Some seem demonic and frenzied, as if the virus writer was driven by a personal animus. On January 15, 1991, the principal bank on the Mediterranean island of Malta was attacked by a particularly vicious bug. The first warning of the virus was an announcement that popped up suddenly on the computer screen: DISK DESTROYER--A SOUVENIR OF MALTA I HAVE JUST DESTROYED THE FAT ON YOUR DISK!! HOWEVER, I HAVE KEPT A COPY IN RAM, AND IM GIVING YOU A LAST CHANCE TO RESTORE YOUR PRECIOUS DATA. WARNING: IF YOU RESET NOW ALL YOUR DATA WILL BE LOST FOREVER!! YOUR DATA DEPENDS ON A GAME OF JACKPOT CASINO DE MALTE JACKPOT +L+~+?+ ~+c+ CREDITS: 5 ANY KEY TO PLAY The virus was, in essence, inviting operators to gamble with the data on their hard disks. It had captured the FAT, the File Allocation Table which, despite its unprepossessing name, is one of the most important components of a computer's hard disk: it is a master index that keeps track of where all the pages for each file are kept. On a hard disk, unlike in a filing cabinet, pages of a single file are not necessarily stored together; they are stored wherever there happens to be disk space, which often results in "fragmentation"-- particularly of larger files. Whenever a user selects a particular file, the FAT is responsible for finding all of the file's parts and assembling them in the correct order. Once corrupted, the FAT takes on all the attributes of an unqualified temporary secretary: it can't find anything, it loses files, and the ones it doesn't lose are incomplete or presented in the wrong order. The gamble the operators faced was more or less the same as on a slot machine-- except that the computer user was playing with data instead of a coin. If he played and lost, the virus would zap the FAT, with disastrous consequences. If he played and won, the virus would replace the FAT it had captured with the copy it had sequestered in the RAM, or random access memory, the computer's principal memory, and the area where programs are run. When the user followed the on-screen instructions and pressed a key, the characters in the three "windows" ran through a sequence, like a real slot machine. The operator had five "credits," or tries, and the game ended when three Ls, Cs, or .~s came up. The operator could try again if a combination of characters came up. The jackpot was three Ls. Then the operator would see the following message on his screen: BASTARD! YOURE LUCKY THIS TIME, BUT FOR YOUR OWN SAKE, SWITCH OFF YOUR COMPUTER NOW AND DONT TURN IT ON UNTIL TOMORROW! Three .~s was a loser: the virus would then announce NO FUCKING CHANCE and destroy the FAT. Three Cs, unsportingly, was also a loser: the message was: HA HA! YOU ASSHOLE, YOUVE LOST: SAY BYE TO YOUR BALLS. Once again, the FAT would be zapped. The Maltese bank had no choice but to gamble. Once the virus had seized control of the FAT, there was no possible way of retrieving it other than by coming up with a jackpot, and the odds against that were three to one. The computer operators pressed their keys, losing two games to every one they won and having to rebuild the system and restore the damaged files on two thirds of their infected computers. They also had to track down and destroy the virus, which became known as Casino, on all of their machines, a process that required the help of a computer security expert from Britain. From the spelling and the use of American expressions such as asshole, it was thought that the author of Casino was American, or perhaps a Maltese who had previously lived in the States. But, L as in so many cases, his identity was never discovered. Casino epitomized many of the characteristics of the new breed 114 APPROACHING ZERO of viruses: it was vicious, destructive, and its payload was curi ously spiteful. To date, the virus hasn't spread from its island home, though that doesn't mean that it won't travel in the future. It is estimated that a virus that is going to travel will reach its peak propagation within eighteen months. (Casino is thought to have been written just a few weeks before it hit the bank.) About half of the viruses ever written are less than six months old: they are, in a manner of speaking, now waiting for their travel documents, for that odd confluence of luck and circumstance that will unleash them throughout the world. As the world population of computer viruses grows exponentially, so does the potential for real disaster. Viruses will affect computer users first, but then, indirectly, many people who have never even touched a computer will be affected. A virus let loose in a hospital computer could harm vital records and might result in patients receiving the wrong dosages of medicine; workers could suffer job losses in virus-ravaged businesses; dangerous emissions could be released from nuclear power plants if the controlling computers were compromised; and so on. Even military operations could be affected. Already, during the 1991 Gulf conflict, Allied forces had to contend with at least two separate virus assaults affecting over seven thousand computers. One of the incidents was caused by the ubiquitous Jerusalem bug, the other by a "fun" virus from New Zealand called Stoned, which displayed the message YOUR PC IS NOW STONED on the screen. The two outbreaks were enough to cause computer shutdowns and the loss of data. The consequences for the military, now utterly dependent on computers, of an attack by one of the newer, more destructive viruses--perhaps one unleashed by the enemy--could be catastrophic. In truth, there has been no major disaster, no loss of life or jobs due to a virus. The only losses to date have been financial. But hospitals have already found viruses lurking in their systems; the military has been affected; and a Russian nuclear power plant's central computer was once shut down because of a virus. None of the bugs were destructive, but it is probably only a matter of time before there is a real catastrophe. It is now believed by many that the real threat from computer viruses will escalate in the mid-nineties when a new generation of bugs begins to spread throughout the industrialized countries of the West. The new viruses will attack from every corner of the world, but the biggest threat will come from one country--Bulgaria. The first call came in to the Help Desk of a California magazme publisher just after five P.M. on Thursday, June 27, 1991.3 The company has 1,500 interlinked computers spread around three buildings. The Help Desk, part of the technical-support department, works as a sort of troubleshooter for the entire networked system, dealing with routine problems and helping the less com- puter-literate staff with their hassles. "My computer has started making a noise," said the caller. In the normal run of events, noises, apart from the standard beep when starting up or the low-pitched whir of the machine's cooling system, are not part of a computer's standard repertoire. A noise usually suggests a problem--a high-pitched whine can be a warning that the computer's monitor is faulty; a loud hum can signal a difficulty with the hard disk. "What sort of noise?" asked the girl at the Help Desk. "I don't know, it's just a noise. I've switched it off. Can someone come over?" Seconds later the Help Desk received a call from another user with the same problem. Then the switchboard lit up. There were callers from all over the company, all with the same complaint: their computers were making odd noises. It may be a tune, one of the callers added helpfully, coming from the computer's small internal speaker. The sixth caller recognized the melody. The computers were all playing tinny renditions of "Yankee Doodle." To the specialists in the technical-support department, the discovery that the tune was "Yankee Doodle" was confirmation that 116 APPROACHINC ZERO they had been hit by a virus, and a well-known one at that. The Yankee Doodle virus had first been seen in 1989 and was said to be relatively harmless. There are a number of variants of the bug but most simply cause computers to play "Yankee Doodle." This particular variant, known as Version 44, played the tune at five P.M. every eight days. The company arranged for antiviral software to be shipped overnight by Federal Express. The publishers of the software assured the Help Desk that they would simply need to run the program on the computers to locate the infected files and kill the virus; the files wouldn't be damaged and no data would be lost. Yankee Doodle was a nuisance, they said, but not a major problem. On Friday morning the technical-support staff began the timeconsuming task of checking every computer in the company. They discovered that eighteen of their machines had been hit by the virus and that the killer function of the software they had just bought wouldn't work on their particular variant of Yankee Doo- dle. Instead, to clean the bug out, they would need to delete all infected files and replace them. The virus they were fighting is generally transferred by diskette. It attaches itself to an executable file--a word-processing program or a game, for instance--then, once loaded on to a computer, it searches out other programs to infect. It is generally harmless in that it never attacks data files, the ones users actually work on, so it can't cause serious damage. Its nuisance value comes in eradicating it: deleting programs and then replacing them can be time-consuming. In the meantime, to stop the virus from spreading any farther, the company decided to shut down the entire network of 1,500 computers, leaving machines and staff idle. The technical-support specialists estimated that killing the bug and replacing the programs would take them two or three hours at the most. But by mid-afternoon they realized that they had underestimated the size of the job, and arranged to come in over the weekend. In the end, the technical staffworked for four days, Friday through Monday, before they were satisfied that all the machines were free of the virus. During that time computers and staff were inactive, neither processing work in progress nor going ahead with anything else. The computers worked well for the next three days, but then, at ten A.M. on Thursday, July 4th, the virus was rediscovered. In a routine scan of one of the computers with the new antiviral software, one member of a small crew working over the Independence Day holiday received a big shock: Yankee Doodle was back. The technical specialists, called into the offices from their homes, discovered to their horror that this time 320 machines had been infected and when they asked the maker of the antiviral software for an explanation, they were simply told, "You missed a spot. The company was forced to shut ctown ItS COmpUlerS agam, and again staff and machinery sat idle while the support staff searched laboriously through every program on all 1,500 machines. There was no damage: the bug was eradicated and the programs reinstalled without even a byte of data lost. But the lack of damage disguised the virus's real cost in downtime. By the time Yankee Doodle had been completely eradicated, the company had suffered one week of lost production, one week in which 1,500 staff were idle, one week of irrecoverable business. The company never quantified its loss, but it is estimated to run into the hundreds of thousands of dollars--all from what was purported to be a harmless virus. Since 1990 virus researchers have pieced together a history of Yankee Doodle. It was first spotted in 1989 in the United Nations offices in Vienna on a computer game called Outrun. The game is proprietary, though unauthorized pirate copies are often passed , around on diskette. Someone, somewhere, is thought to have infected a copy of the game, accidentally or deliberately, and the Virus began its travels, first to Vienna, then around the world courtesy of the United Nations. Though there are known to be fifty-one versions of the virus, they are all based on one original 118 APPROACHING ZERO prototype. And that program, despite the virus's all-American name, was written in Bulgaria. In the same month that the California publishing company was trying to eradicate Yankee Doodle, a major financial-services house on the other side of the country was hit by another bug. This one wasn't a joke; it was deliberately malicious. The first symptoms appeared when one of the secretaries was unable to print out a letter she had just entered into her computer. In such cases people usually follow the same routine: the secretary checked the paper, switched both the computer and the printer off and on, and then fiddled with the connecting cables. Still nothing printed out. Finally she rang her company's technical-support office. When the specialist arrived, he began running tests on the affected machine. First he created a new document and tried printing it out, but that didn't work. He then guessed that the word-processing program itself was defective, that one of its files had become corrupted and was preventing the machine from printing. He went to another computer and copied out the list of program files used by the company, which showed the names of the programs and their size, in bytes (or characters). He then compared the files on the problem machine with the list. Everything matched, except that eight of the files on the affected computer were slightly larger than on the other. He checked the differences, and in each case the files on the problem machine were exactly 1,800 bytes larger. With that information, the specialist knew immediately that the company had been hit by a virus; he also knew it was 1,800 bytes long and attached itself to program files. He called his supervisor, who hurried over with a virus-detection diskette. They inserted it in the infected computer and instructed it to check the machine for viruses. Program file names appeared briefly, one by one on the screen, as the virus detector bustled through its checks, examining each file for known bugs. After five minutes, a message appeared on the screen: it stated that eighty-three files had been checked and no virus had been found. In exasperation, the supervisor called the vendor of the virus-detection program. lt does sound like you've got a virus," the vendor agreed. 'But if it's not getting picked up by our software, then it must be a new virus. Or a new strain of an old one." Most virus-detection programs operate by looking for known characteristics of familiar viruses--in other words, for a string of text or a jumble of characters that is known to be contained within the program of a previously discovered bug. Such virusdetection kits are, of course, unable to detect new or modified viruses. At the suggestion of the vendor, the technical-support staff began a search of one of the infected files, looking for text or ~messages. Specialized software is needed to inspect the inside of ffll program file; during the inspection the screen displays a jumble ~'of computer code. But within the code the staff saw two strings of text: EDDIE LIVES . . . SOMEWHERE IN TIME! said the first. The second announced: THIS PROGRAM WAS WRITTEN IN THE CITY OF SOFIA 1988--1989 (C) DARK AVENGER. The supervisor phoned the vendor again: "Who the hell is the Dark Avenger?" The short answer, the vendor explained patiently, is that no one knows. The Dark Avenger is an enigma. Most virus writers remain anonymous, their viruses appearing, seemingly, out of the ether, without provenance or claimed authorship, but the Dark Avenger is different: not only does he put his name to his viruses, he also signals where they were written--Sofia, the capital of Bulgaria. The Dark Avenger's viruses began seeping into the West in 1989. They are all highly contagious and maliciously destructive. "The virus you've been hit with is called Eddie, or sometimes the Dark Avenger, the vendor told the increasingly worried technical-support supervisor. "It must be a new strain or something. That's why it wasn't picked up. Is there any other text message, a girl's name?" The supervisor took a closer look at the virus. "I missed it 120 APPROACHING ZERO before. There's another word here, Diana P. What does this thing do?" "Well, as it's a new version, the answer is I don't know. Until we've seen a copy, it's anybody's guess." To discover what a virus actually does, it has to be disassem bled, its operating instructions--the program--taken apart line by line. This is a difficult and time-consuming process and can be carried out only by specialists. In the meantime the technical support staffcould only wait and watch as the virus spread slowly through the company, bouncing from machine to machine via the network cables that interlinked the company's 2,200 computers. Viruses like Eddie work by attaching a copy of themselves to an executable file; whenever an infected program is used, the virus springs into action. It usually has two tasks: first, to find more files to infect; then, after it has had enough time to spread its infection to release its payload. It was obvious that Eddie was spreading so it was already performing its infection task. What was worrying was what its payload would prove to be. To arrest the spread of the bug, it was decided to turn off all the computers in the company and wait until the virus could be cleaned out. It was a difficult decision--it would mean downtime and lost business--but it was a sensible precaution. It was later discovered that the payload in the Eddie variant was particularly malicious. When unleashed, it takes occasional potshots at the hard disk, zapping any data or programs it hits. The effect is equivalent to tearing a page out of a book at random. The loss of the pages may not become evident until one can't be found. But on a computer, if the loss goes undetected over a period of time, then the backup files, taken as a security measure in case of problems with the originals, could also have pages missing. The slow corruption of data is particularly insidious. Any computer breakdown can cause a loss of data, necessitating some reentry of the affected transactions since the last backup. But if the backups are also affected, then the task could become impossible. At worst, the data could be lost forever. In this instance some data was irrecoverably destroyed, even though only sixty machines were found to be infected. But, in a sense, the company had been lucky: because Eddie had taken a potshot at a secretary's word-processing program and knocked out its print capability, it was discovered fairly early on. Had it lurked undetected for longer, it could have destroyed even more data. The process of checking all 2,200 computers in the company took four and a half days, with a team of twelve people working twelve hours a day. Every executable file on every hard disk on every machine had to be checked. The team had special programs to help with the task, but viruses could easily get wrapped up inside "archived" files--files that are compressed to save computer space-- where they can escape detection. All archived files had to be expanded back to their full size, checked, and then packed away again. That took time. Also, all diskettes had to be checked, a nearly impossible task given the difficulty in finding them: diskettes have a habit of disappearing into black holes in desk drawers, in briefcases, in storage cupboards. The computer diskette has now assumed the generality of paper as a medium for storing information. Staff with home computers often carry diskettes to and from their office, and it makes sense that diskettes containing valuable data should be stored off-site, as a precaution against problems with the office computer. But the home PC also encourages the transfer of viruses among fami- lies. A student might transfer a virus from college to home; a parent might transfer a virus from home to office. For the most j part, viruses are spread innocently, but there is now such a large f~ traffic in diskettes that it is usually impossible to trace the source of an infection. After seven hundred hours of intensive effort, the technicalf~' support staff felt confident they had eliminated all traces of Eddie. Their confidence was short-lived. Within a week Eddie was back. This time they lost a further one and a half days' work. (Because it is very difficult to remove all traces of a virus, 90 percent of victims suffer a recurrence within thirty days.) After the final bout of Eddie was cleared away, executives of 122 APPROACHING ZERO the company tried to quantify how much the bug's visit had cost them--not that any of it would be recoverable from insurance. "We lost $500,000 of business-- really lost business, not orders deferred until we could catch up, but business that had to be done there and then or it went to a competitor," said the company's chief financial officer. "We also lost data. That cost us $20,000. But what really hurt was the lost business. If we force a customer into the hands of a competitor, he might go there again. I guess that could cost us another $500,000." The company tried to find out how the virus had got into its machines in the first place. Sometimes disenchanted employees (or ex-employees) have been known deliberately to cause havoc on computer systems, but it seemed unlikely in this case. The company concluded that the infection was almost certainly accidental, probably introduced on a diskette brought in from outside. All they knew for certain was that some Bulgarian who called himself the Dark Avenger had cost them $1 million. Meanwhile, across the Atlantic in England, computer operators in government offices in Whitehall and regional centers were confounded by a new virus that spread, seemingly unstoppably, from office to office and department to department. The virus was first observed in the House of Commons library in the Palace of Westminster. In early October 1990, researchers at the library became concerned about one of their computer systems. The library operates a PC-based research service for members of Parliament, providing information, background, and documentation on subjects of concern. Part of the service uses a network of Compaq computers, and it was this system that was causing problems. Computer files that should have been available suddenly appeared to be missing, while others were corrupted or incomplete, and some of the file names were distorted. As the days went by, the problems multiplied, and the head of computer systems at the library called in an outside specialist. A virus-detection program run on one of the affected machines came up clean, but from the way the computers were malfunctioning, the specialist was convinced that the House of Commons library had been hit by a virus. He compared the lengths of the program files on an infected machine with those on a clean computer. As expected, the programs on the infected computer were longer, which suggested the unknown virus was attaching itself to the ends of program files. A visual inspection of the virus followed, revealing one full word in the jumble of characters on the screen: NOMENKLATURA. The word is of Russian origin, though in common use throughout Eastern Europe. It was the name given to the upper echelons of the Communist party and the high-ranking bureaucrats--the .class that did well from the old system, those who had access to ; the special shops and the special rations, the cars and the country homes. It is a pejorative now and was almost certainly picked by the virus writer for its ironic overtones. A copy of the virus, immediately nicknamed Nomenklatura, was sent to a British researcher, Alan Solomon, who runs a specialist computer data-recovery service from Berkhamsted, northwest of London. When he disassembled the bug, he found he was looking at one of the most destructive viruses he had ever seen. The virus's target proved to be the FAT, the all-important File Allocation Table. With the FAT corrupted, the computer would be unable to reassemble data files in the correct order--hence the gaps in the information accessed in the House of Commons library. Solomon also noticed a string of text characters within the Nomenklatura program. It could be a message, he thought, except that the text was represented on his computer screen by a code that appeared to refer to non-English-language characters, which looked like Greek or Russian. Solomon guessed it was Bulgarian. To confirm his hunch, Solomon dialed an electronic bulletin board in Sofia, linking to the East European country via Fidonet, an international public-access computer network run by hobby- 124 APPROACHING ZERO ists. The board he accessed was owned by MicroComm, a subsidi ary of the Bulgarian public telephone company. Once linked to the board, he managed to make contact with one of the company's engineers, Veni Markovski, who spoke a little English Solomon uploaded the code to Sofia, and Veni looked at it with his Cyrillic converter. If the code represented Cyrillic characters the converter--a program that translates keyboard strokes into Cyrillic--would recognize them and display the message in the virus. The text, though, would be in Bulgarian, which was why Solomon needed Veni's help. The converter rapidly deciphered the code, changing it to Cyrillic. Solomon had guessed correctly. The phrase, Veni reported, was an idiomatic Bulgarian expression. It took some time to translate--Veni's English is poor--and its meaning is obscure. But, Veni said, it translates to something like: "This fat idiot instead of kissing the girl's lips, kisses quite some other thing." Solomon wasn't surprised that the message was in Bulgarian. By 1990 everyone involved in computer security had become aware that something odd was going on in that obscure East European country. Increasingly sophisticated and damaging viruses that affected IBM-type PCs were moving into the West, carried on diskette or transferred by electronic bulletin boards, and all had one thing in common: they had been written in Bulgaria. Though only a few of the viruses had actually been seen "in the wild"--that is, infecting computers--reports from Bulgaria suggested that two new viruses were being discovered in that country every week. By mid-1990 there were so many reported Bulgarian viruses that one researcher was moved to refer to the existence of a "Bulgarian virus factory." The phrase stuck. The origins of that factory go back to the last decade. In the early 1980s the then president of Bulgaria, Todor Zhivkov, decided that his country was to become a high-tech power, with computers managing the economy while industry concentrated on manufacturing hardware to match that of the West. Bulgaria he decided, would function as the hardware-manufacturing center for Comecon (Eastern Europe's Council for Mutual Economic Assistance, now defunct), trading its computers for cheap raw materials from the Soviet Union and basic imports from the other Socialist countries. Bulgaria had the potential, in that it had many well-educated young electronics engineers; what it didn't have, with its archaic infrastructure and ill-managed economy, was any particularly useful application for its own hardware. With the resources of the state behind Bulgaria's computerization, the country began manufacturing copies of IBM and Apple models. The machines were slow-- very slow by today's standards--and were already obsolete even when they first started crawling off the production line. They had been "designed" at the Bulgarian Academy of Sciences, but without the help or blessing of either IBM or Apple. The Bulgarian machines were simply poorly manufactured clones that used the same operating systems and computer language as the real IBMs and Apples. In the latter half of the 1980s shiny new computers started to appear in state organizations, schools, colleges, and computer clubs. Many were destined to sit on the boss's desk, largely unused, symbols of a high-tech society that never really existed. Few businesses had any real need for computers; some used them simply to store personnel records. It was a gloss of technology laid over a system that, at its core, wasn't functioning. In addition, Bulgaria didn't have any software. While the factories continued to manufacture PCs, the most basic requirement--programs to make the machines function had to be pirated. So the Bulgarians began copying Western programs, cracking any copy-protection schemes that stood in their way, and became more and more skilled at hacking--in the classic sense of the word. They could program their way around any problem; they learned the ins and outs of the IBM and Apple operating systems; they became skilled computer technicians as they struggled to keep their unreliable and poorly manufactured computers func- tioning. In short, they were assimilating all the skills they would need to become first-class virus writers. The first Bulgarian viruses to arrive in the West were seen in 126 APPROACHING ZERO 1989. They became increasingly sophisticated and malignant progressing within a year from the relatively harmless Yankee Doodle to the more destructive Eddie and then to Nomenklatura, which was deadly. Nomenklatura's attack on the House of Commons library had zapped data in the statistical section, rendering valuable informa tion irrecoverable. From the House of Commons, the virus began to journey through other sectors of the British government, presumably carried on diskettes from the library. The virus traveled slowly, popping up first in one department, then spreading to another. As soon as it was wiped out in one office, it would reappear elsewhere; it has not been completely eradicated to this day. Alan Solomon, a computer security specialist who worked on the case, is convinced that Nomenklatura's creator is the Dark Avenger. In November 1988 stories about Robert Morris, Jr., and the Internet Worm were published in Bulgaria. The news, already exaggerated in the American press, became even more fanciful by the time it was retold in Bulgarian newspapers. The worm excited the curiosity of two young men, Teodor Prevalsky and Vesselin (Vesko) Bontchev. They had been close friends for many years, had gone to university together, and had served side by side as officers in the Bulgarian army. Aged twentyseven, they were both engineering graduates from professional families, which made them part of the privileged class in Bulgaria at the time. The Bulgarian computer industry was in full swing by then, but the country had few uses for the new machines. In response, a magazine was started called Komputar za vas ("Computer for You"), to show readers how to do something constructive on their relatively worthless PCs. The magazine needed technical writers who could explain how the machines worked, and Vesko, provided with desk space at the magazine's offices, found that he could double his income of $45 a month by writin~ the articles. By Bulgarian standards his salary was already high; with the additional income from the magazine he was positively wealthy. When news of the Internet Worm broke, Vesko and his friend Teodor discussed it at length. For Vesko, it would be the inspira,tion for an article; for Teodor, it was the catalyst for a new 1intel1ectual pursuit. On November 10, 1988, Teodor sat down at a computer at the technical institute where he worked and started to write his first virus. He had managed to get a copy of Vienna, which had been copied from Ralf Burger's book, and he used it as a model for his own bug. On November 12th Teodor proudly made an entry in his diary: "Version 0 lives." Version 0 was, in all probability, the first homegrown Bulgarian virus. It did very little except replicate, leaving copies of itself on what are called COM files--simple program files of limited length, used for basic computer utilities. When the virus infected a file, it beeped. Just two days after writing Version 0, Teodor had prepared Version 2.4 It was more clever than the original in that it could infect both common types of executable files: COM and EXE. The latter are the more sophisticated programs-- like word-processing, for instance--and because they are structurally complex they are more difficult to infect. But Teodor's Version 2 employed a little trick that would convert the shorter EXE files into COM files. When the operator called up, or loaded, an EXE file, the lurking virus saw the load command, jumped in ahead and modified the structure of the EXE file so it resembled a COM file. The next time a restructured EXE file was loaded up, it could be successfully infected by the virus, just like an ordinary COM file. Teodor was also experimenting with anti-virus software at the time, and developed a program that would hunt down and kill Versions 0 and 2. It was called "Vacsina," the Bulgarian word for vaccine. However, by Version 5 Teodor had adapted his virus so that it was immune to his own killer program. He accomplished this by simply adding the character string "Vacsina" to the virus. 128 APPROACHING ZERO When his anti-virus program saw the string, it would leave the bug alone. It was shortly thereafter that Version 5 escaped. Like most Bulgarians, Teodor had to share his computer with colleagues at the Technical Institute; with four people using one machine, with software copying rampant, and with the casual transfer of diskettes, it was only a matter of time before one of the bugs began to propagate out of his control. Within weeks Version 5 had spread throughout Bulgaria. In less than a year it had reached the West--the first Eastern virus to jump the Iron Curtain. When the virus was examined, researchers discovered the text string "Vacsina," which immediately gave a name to Version 5. Meanwhile, Teodor continued experimenting. By December 15, 1988 he had advanced to Version 8. On this variant the payload--the innocuous beep--now sounded only when an infected computer was restarted from the keyboard (a "warm reboot"), allowing it to remain hidden for longer. In the best programming tradition, all his improvements were duly documented and given version numbers as they appeared. Later in December a new Bulgarian virus was discovered. It carried a text string which said it had been authored by a Vladimir Botchev. The bug was almost certainly written in response to one of Vesko's magazine articles: in November Vesko had stated that it would be "difficult" to write a virus that could infect all EXE files, including the longer ones, and Vladimir had presumably seen that as a challenge. His virus appeared less than a month after the article was published. It employed a novel and technically elegant device that enabled it to attach itself to any EXE file, no matter what length. After it infected a file it played the tune "Yankee Doodle"--in celebration, perhaps. This virus was generally not damaging--its payload was the tune--and because it was easy to detect, it never spread. But lhe new bug's payload was immediately copied by Teodor in his new variant, Version 18, which appeared on January 6, 1989. This OnC didn't beep; instead it played "Yankee Doodle," which Teodor had lifted, note for note, straight from Vladimir's program. Five days later, Teodor produced Version 21, which could remove the virus from infected files if a more recent version of this bug attacked the same system. Then, on February 6, 1989, Version 30 appeared. It incorporated a "detection and repair" capability, that would warn the virus if it had been modified or corrupted while replicating. Eerily, it could then fix the damage i tself by changing the corrupted instructions back to their original form. It was a kind of artificial life, though the repair capability was limited (it could handle only changes of up to 16 bytes in length). By the end of February Teodor was on to Version 39 and his virus was now full of tricks: it could infect EXE files of any size, 3, it could even evade antiviral software. As soon as it noted the presence of a detection program, it would detach itself from the infected file and hide elsewhere in the computer's memory. With Version 42, which appeared in March, his virus took on a new role: virus fighter. The Ping Pong boot-sector virus, which is believed to have been created at Turin University in Italy, had now reached Bulgaria. Ping Pong (also called Bouncing Ball) was a joke virus: from time to time it simply sent a dot careering around the screen, like a ball in a squash court. Teodor's new virus could detect Ping Pong and was able to modify it in such a way that, after a time, it destroyed itself, leaving behind its corpse. He persisted with the tune "Yankee Doodle" as his payload, but he varied the time and frequency it would play. One of his next variants was Version 44, which plays the tune every eight days at 5 P.M. This was the version destined to become the most widely traveled of all Teodor's viruses: once again, it escaped from his office machine, probably on a diskette, and spread through Bulgaria; on September 30, 1989 it was sighted in offices of the United Nations in Vienna; and from there, now known as Yankee Doodle, it traveled the world. It was this version which caused mayhem at the California publishing house in July 1991. Teodor continued to develop his virus. The last variant was Version 50, by which time it had been given the additional power to detect and destroy the Cascade bug, which had just arrived in 130 APPROACHING ZERO Bulgaria from Austria. Cascade was another joke virus: it caused the letters on a computer terminal to fall down and pile up in heaps at the bottom of the screen to an accompanying clicking noise. After it had finished its performance, a user could resume his work--though he would need to replace the letters and words that had fallen from his screen. It wasn't particularly damaging, though the operator's nerves could well have been frayed. After Version 50 Teodor began to explore some of his other ideas. One was a joke virus that hopped around a hard disk while challenging the operator to FIND ME! It was unusual in that it was nearly undetectable: unlike other viruses, Find Me! wouldn't infect the boot sector or a program file. It created its own home within infected systems by stealing the name of an EXE file and attributing it to a new COM file; this new COM file became its hiding place.5 It was a clever trick. Teodor knew that on computers with two files of the same name the COM file is always loaded prior to the EXE file. So his little bug would get to the screen first, to taunt the operator with "Find Me!" messages. If the operator looked at his list of files he might notice that he had an extra COM file with the same name as one of his EXE files, but he generally wouldn't realize the significance. Even if he did, the bug would probably be one step ahead of him. From time to time, Find Me! would create a new COM file (always with the same name as an EXE file) and transfer itself to a new home, deleting the old one as it did so. In that way it continued to hop around the hard disk, usually well ahead of the increasingly irritated operator. It was possible to remove the bug completely, but it invariably took a few manhours of frustrating chasing. Teodor also experimented with "stealth" viruses--silent, deadly, and almost undetectable bugs that evade antiviral software in much the same way that the Stealth plane evades radar detection. Stealth technology has been exploited by virus writers since 1986 (the Pakistani Brain virus has some stealth capability in that it is able to camouflage its presence on the boot sector), but Teodor's was the first that could add itself to a program file without, apparently, increasing the length of the file. Of course it was only an illusion: the virus would simply deduct its own length from the infected file whenever it was being examined. With his stealth bug Teodor had more or less reached the pinnacle: there was little he could do to improve the programming of his latest virus except, perhaps, to add a destructive payload. But, for Teodor, destruction of data or programs was never the point. He wrote viruses as an intellectual challenge. None of his viruses had ever been intentionally damaging, though he had become aware that they could cause collateral losses. He had also realized that a completely harmless virus was an impossibility. All viruses, by their mere presence on a computer, can accidentally overwrite data or cause a system to crash. And the most dangerous of all, he thought, was an undetectable virus that could spread unstoppably, causing collateral damage without the operators even being aware they were under attack. In 1989 Teodor decided to retire from virus writing. His own career up until then had, curiously, mirrored his friend Vesko's. While Teodor wrote viruses, Vesko wrote about them; as Teodor became more proficient at writing bugs, Vesko became more accomplished at analyzing them. By 1989 Vesko had become Bulgaria's most important virus researcher and a major contributor to Western literature on the subject. He had been invited to submit papers and to lecture at Western European computer security conferences: he was recognized as an authority on viruses, particularly those from Eastern Europe. Vesko's reputation was due, in a large part, to having been in the right place at the right time. First, there were his friend Teodor's bugs. Teodor would often pass on the programming code to Vesko for analysis, who would then report on their capabilities in the local press and in Western journals. It was a convenient arrangement, and the resulting publicity would encourage other writerS. Eventually, what became known as the Bulgarian virus factory started to pump out bug after bug, each more dangerous 132 APPROACHING ZERO than the last, and Vesko was there to record it. He was in the eye of the storm, collecting viruses from all over Bulgaria as they spread from computer to computer. By 1991 he was reporting two new locally grown viruses each week. In a country with so many bugs flying around, it was inevitable that Bulgarian computers would become overrun. Most computers in the country had been hit at least once; many had been hit with multiple viruses at the same time. Because Vesko was the country's leading authority on the malicious programs, he was eventually given responsibility for coordinating Bulgaria's effort to fight them off. He was constantly on call. Days he worked in his office in the Bulgarian Academy of Sciences, where he was given the dour title of Assistant Research Worker Engineer. Weekends and nights he continued the fight from his own cramped room on a borrowed Bulgarian clone of an IBM PC. He dealt with ten to twenty phone calls each day from institutions or firms that had been attacked by viruses. By then the Bulgarian virus factory was in full production. It was no longer a matter of Vesko and his friend Teodor, one a researcher, the other a virus writer. Bulgaria had spawned some of the most skilled and prolific virus writers in the world. In Plovdiv, Bulgaria's second largest town, a student named Peter Dimov produced a series of viruses "as revenge against his tutor" and another two "in tribute" to his girlfriend, Nina (it is not known if she was pleased). One of Peter's ambitions was to write the world's smallest virus: his first came to under 200 bytes. Later he wrote one only 45 bytes long. For a few weeks it was the shortest virus known--until another Bulgarian programmer produced one that was just 30 bytes. Peter was also the author of the first Bulgarian boot-sector virus as well as two ominous-sounding bugs that he called Terror and Manowar. But despite their names, neither was particularly damaging. In total, Peter wrote around twenty-five viruses. In Varna, on the Black Sea, two students at the MathematicS Gymnasium (Upper School), Vasil Popov and Stanislav Kirilov, produced a series of viruses and trojans. Their most dangerous, called Creeping Death (or DIR-2),6 was reported to be able to infect all the files on a hard disk within minutes. Lubomir Mateev, then a twenty-three-year-old university student, and his friend Iani Brankov wrote a virus together to embarrass their professor when they were studying at Sofia University. Their first bug was programmed to make a shuffling noise while he was lecturing that sounded like the rustling of paper. This virus and a subsequent variant (which borrowed the bouncing-ball payload from Ping Pong) became known as Murphy 1 and Murphy 2.' Highly infectious, they spread throughout Bulgaria and reached the West in 1991. Many other programmers and students took a stab at writing nruses, with varying degrees of success. It became something of a fad among computer freaks in Sofia and other Bulgarian cities in the late 1980s. There was, of course, no "factory" in the usual sense of the word--just a group of young men (they were all male), probably unknown to each other, who had learned the tricks of writing viruses through the techniques perfected while stealing Western software. The value to Bulgaria of all the virus-writing activity was negligible. Though the programmers who compiled the bugs were, no doubt, honing their skills, and some of the viruses demonstrated a cleverness and technical dexterity that may have been admirable, viruses simply do not have any productive purpose. Indeed, Fred Cohen--the man who coined the term "computer virus" in the first place-- once tried to find a role for them and organized a competition to write a beneficial virus. None was found. In any event, in late 1990 and early 1991, Bulgaria itself, no longer Communist and not quite democratic, was going through an identity crisis. Public confidence in the government, in state institutiOns, and in the currency had evaporated, to be replaced by a deeply cynical, almost anarchic national ethos. Bulgaria had become a country of shabby, small-time dealers, of petty blackmarketers and crooked currency changers. The symbols of the 134 APPROACHING ZERO immediate past, of the near half-century of Communism, had been pulled down; little had been erected in their place. But the computers that President Zhirkov had decreed would turn Bul garia into a modern technological power remained, and indeed offered themselves to the new generation of computer programmers as weapons to be turned against the state, to drive an electronic stake through the heart of the system. Viruses would cripple Zhivkov's dream. In this gray time of shortages and rationing, of cynicism and despair, writing viruses was a sort of protest--perhaps against the Communists, possibly against the transitional state, almost certainly against the lack of opportunity and hope. Writing viruses was a form of individualism, of striking out; it was also an opportunity for notoriety. Since 1988 the Bulgarian virus factory has produced around two hundred new viruses. Most have yet to travel; only a few have reached the industrialized West. The scale of the problem may not become apparent for several years. Some of those who created the viruses are known, some aren't, but the greatest threat is Bulgaria's most proficient and fearsome virus writer: the Dark Avenger. The man who was to become known as the Dark Avenger began work on his first virus in September 1988. "In those days there were no viruses being written in Bulgaria, so I decided to write the first," he once said. "In early March 1989 it came into existence and started to live its own life, and to terrorize all engineers and other suckers." The Dark Avenger had started work on the virus known as Eddie just weeks before Teodor had sat down to write the first of what became his Vacsina-Yankee Doodle series. Teodor's virus was ready first, but the Dark Avenger's bug was much more malicious and infective. "It may be of interest to you to know that Eddie is the most widespread virus in Bulgaria. I also have information that Eddie is well known in the U.S.A., West Germany, and Russia too," the Dark Avenger once boasted. The Dark Avenger likes to leave teasing references to his identity in his viruses. As in the Eddie virus, he sometimes "copyrights" his bugs, and often gives Sofia as the source. The text strillg DIANA P. was assumed to be a reference to his girlfriend, exccpl that Diana isn't a particularly Bulgarian name. It's now belicvcd to be a reference to Diana, Princess of Wales. The Dark Avenger also likes heavy-metal music: the other text string in his first virus, the mysterious EDDIE LIVES . . ., apparently refers to the skeletal mascot, Eddie, used by the British heavymetal group Iron Maiden in their stage act. Heavy-metal symbols and motifs run through many of the other viruses written by the Dark Avenger. A family of perhaps twenty or more viruses can be attributed to him, all technically advanced, most deliberately ma- licious, some containing text strings that use the titles of Iron Maiden tracks: "Somewhere in Time," "The Evil That Men Do," and "The Good Die Young." His viruses also mimic the posturing Satanism of heavy-metal music. His Number of the Beast virus (the name is yet another reference to an Iron Maiden song) contains the 3-byte signature "666," the mystical number believed to refer to "the beast," the Antichrist in the Book of Revelations. Perhaps appropriately, of all the viruses attributed to the Dark Avenger, Number of the Beast is considered the most technically accomplished. A stealth virus, it exploits an obscure feature of the standard PC operating system to evade detection and hide in unused space on program files so that it doesn't change the length of the host file. Oddly, the virus doesn't have a payload, though its mere presence on a PC is likely to cause it to crash. The Dark Avenger has produced four versions of Eddie and six versions of Number of the Beast, as well as four variants of a virus called Phoenix and four of another one known as Anthrax (the name of an American heavy-metal group). He is also generally believed to have written Nomenklatura, the virus that attacked Britain s House of Commons library, principally because the bug is technically sophisticated and vicious and employs techniques that have been seen in his other viruses. In a way, the Dark 136 APPROACHING ZERO Avenger has become so well known that any particularly destruc tive and clever Bulgarian virus will almost automatically be attributed to him. The alternative is too dire for the computer security industry to contemplate. The Dark Avenger's fame was evident from the response to his calls to the world's first "virus exchange" bulletin board, which was established in Sofia by twenty-year-old Todor Todorov on November 1, 1990. The idea was eventually copied by others in Britain, Italy, Sweden, Germany, the United States, and Russia, but Todorov was the first. The board describes itself as "a place for free exchange of viruses and a place where everything is permitted!" Todorov built up a large collection of viruses after callers learned of his exchange procedures. IF YOU WANT TO DOWNLOAD VIRUSES FROM THIS BULLETIN BOARD, JUST UPLOAD TO US AT LEAST 1 VIRUS WHICH WE DON'T ALREADY HAVE. THEN YOU WILL BE GIVEN ACCESS TO THE VIRUS AREA, WHERE YOU CAN FIND MANY LIVE VIRUSES, DOCUMENTED DISASSEMBLIES, VIRUS DESCRIPTIONS, AND ORIGINAL VIRUS SOURCE COPIES! IF YOU CANNOT UPLOAD A VIRUS, JUST ASK THE SYSOP [SYSTEM OPERATOR] AND HE WILL DECIDE IF HE WILL GIVE YOU SOME VIRUSES.8 The Dark Avenger made his first call on November 28, 1990, four weeks after the bulletin board was set up. I'M GLAD TO SEE THAT THIS BOARD lS RUNNING, he wrote Todorov. I'VE UPLOADED A COUPLE OF VIRUSES TO YOU. I HOPE YOU WILL GIVE ME ACCESS TO THE VIRUS AREA. To which Todorov replied, THANK YOU FOR THE UPLOAD. YOUR SECURITY LEVEL HAS BEEN UPGRADED . . . AND YOU HAVE ACCESS TO THE VIRUS AREA NOW. IF YOU FIND ANY OTHER VIRUSES, PLEASE UPLOAD THEM HERE. When it was learned that the Dark Avenger frequented Todorov's bulletin board, other users began leaving messages for him. HI. DARK AVENGER! WHERE HAVE YOU LEARNED PROGRAMMING? AND WHAT DOES EDDIE LIVES MEAN? AND WHO IS DIANA P. ? IS s~E YOUR GIRLFRIEND OR WHAT? The queries were from Yves P., a French virus writer. Free Raider posted his salute on December 9th: Hl, BRILLIANT VIRUS WRITER. Another message said, Hl, I'M ONE SYSOP OF THE INNERSOFT BULLETIN BOARD. SHOULD I CONSIDER ~IY BOARD NOT POPULAR BECAUSE YOU DON T LIKE TO CALL IT? PLEASE GIVE IT A CALL. The messages from his fans reflected the Dark Avenger's new status: he had become a star. In the two years since he created Eddie, he had become the computer underworld's most notorious virus writer. He had established a brand identity: the Dark Avenger's viruses were known to be the most destructive and among the best engineered ever seen. His fame, as he knew, had spread throughout Europe and to North America as well. So it's not surprising that he wanted to be treated like the star he was, and reacted badly to criticism. In March 1991 he sent the ~following message to Fidonet, the international bulletin board network: HELLO, ALL ANTIVIRUS RESEARCHERS WHO ARE READING THIS MESSAGE. I AM GLAD TO INFORM YOU THAT MY FRIENDS AND I ARE DEVELOPING A NEW VIRUS, THAT WILL MUTATE IN 1 OF 4,000,000,000 DIFFERENT WAYS! IT WILL NOT CONTAIN ANY CONSTANT INFORMATION. NO VIRUS SCANNER CAN DETECT IT. THE VIRUS WILL HAVE MANY OTHER NEW FEATURES THAT WILL MAKE IT COMPLETELY UNDETECTABLE AND VERY DESTRUCTIVE! Fidonet may not have been the best outlet for his boasting: its users are mostly ethical computer enthusiasts. The Dark Avenger received a flood of replies, from all over Europe. Most were critical; some were abusive. The Dark Avenger replied testily, I RECEIVED NO FRIENDLY REPLIE~S TO MY MESSAGE. THAT'S WHY I WILL NOT REPLY TO ALL THESE MESSAGES SAYING "FUCK YOU." THAT'S WHY I WILL NOT SAY IY MORE ABOUT MY PLANS. At thirty-one, Vesko Bontchev is surprisingly young looking, thin and somewhat frail. He is a serious man who speaks deliberately and intensely about the virus problem in Bulgaria. He lives with 138 APPROACHING ZERO his mother in a shabby five-story 1950s block on a characteristically grim East European housing estate on the outskirts of Sofia. The apartment is large by Bulgarian standards: Vesko has his own room. Although he is unassuming, it is apparent that he is proud of his reputation as the country's foremost virus fighter and of his contacts with other researchers in the West. His position is ensured by his oddly symbiotic relationship with the Dark Avenger, one that almost parallels his earlier relationship with Teodor. Because the Dark Avenger lives in Bulgaria, Vesko's position as a lecturer and researcher is secure. At the same time, Vesko contributes to the Dark Avenger's fame by publicizing his activities abroad. In a curious way the two need each other. Cynics who have noticed this have argued that if the Dark Avenger hadn't existed, it would have been in Vesko's interest to have invented him. Some have even theorized that the two are one and the same: that the quiet, intense virus researcher has an alter ego--the demonic, heavy-metal fan, the admirer of Princess Diana, the virus writer called the Dark Avenger. The Avenger has himself contributed to the notion: one of his viruses contains Vesko's own copyright notice, and every so often he teases Vesko. Once, the Dark Avenger wrote: "To learn how to find out a program author by its code, or why virus-writers are not dead yet, contact Mr. Vesselin Bontchev. So, never say die! Eddie lives on and on and on . . ." In an interview in a Bulgarian newspaper, Vesko was asked about the rumours. "Can you give me the name of Dark Avenger?" the reporter queried. "No." "Is it possibly you?" "I have been asked similar questions both in the West and in the Soviet Union. But it is not true." Despite the rumors, Vesko isn't the Dark Avenger--but he does provide the oxygen of publicity for the Bulgarian virus writer. It suits them both: for Vesko, the Dark Aven~er provides the raw material for his reports; for the Dark Avenger, Vesko's ~vatchfulness ensures his own reputation as the demonic scourge of computers. The two young men--the hunter and the outlaw--are locked in an unfriendly embrace. The relationship between the two is one of mutual distrust, which neither attempts to disguise. It is the clas~ic relationship between a cop and his adversary: hatred, tinged with a measure of respect. On several occasions, Vesko says, he has tried to smoke out the virus writer. Once Vesko announced that he had carefully analyzed two viruses attributed to the Dark Avenger: the Number of the Beast and Eddie. He said that, in his view, they could not possibly be the work of the same writer. One was clever, the work of a professional, the other sloppy, the work of an amateur. Furthermore, he said that he intended to present his evidence at a lecture that would be held in Sofia. He guessed that the Dark Avenger would appear, if only to hear what Vesko had to say about his programs. The meeting was well attended, particularly for a cold Friday night in early December. Vesko presented his evidence. Number of the Beast, he said, was obviously written by an extremely skilled specialist whose style contrasted in every way with the poor quality of Eddie. He watched the audience during his presentation, Vesko says, looking for someone who might be the Dark Avenger; during the questions and discussion afterwards he listened for anyone defending the programming of Eddie. He saw and heard nothing that gave him any clues. But two days after the lecture he received a letter from the Dark Avenger. According to the letter, the virus writer had attended the meeting. Vesko published his comments in the magazine Komputar za ~/.s. "The author of the Eddie virus is writing to you," the Dark Avenger began. "I have been reading your pieces of stupidity for quite a long time but what I heard in your lecture was, to put it boldly, the tops." The virus writer went on to complain about Vesko~s critique of his programming skills. Then he added: 140 APPROACHING ZERO "I will tell you that my viruses really destroy information but, on the other hand, I don't turn other people's misfortunes into money. Since you [get paid to] write articles that mention my programs, do you not think I should get something?" Virus writing is not a lucrative field. The Dark Avenger had once before alluded to getting paid for his skills, in a message to a local bulletin board operator, when he had suggested, none too hopefully, that "maybe someone can buy viruses." So far as is known, he has never sold any of his bugs. In 1990 Vesko put together a psychological profile of the Dark Avenger, a compilation of all the known facts about him: his taste in music, his favorite groups, his supposed interest in the Princess of Wales, his need for money and so on. From his letter Vesko gleaned he had been a student at Sofia University and, from sarcastic remarks he had made about Vesko's engineering degree, that he was either a mathematics or science student (there is a traditional rivalry between engineering and the other two faculties). He sent the profile to seven former students at the university, asking if they knew anyone who fitted the criteria. All seven replied, Vesko says, and all seven mentioned the same name- -that of a young man, then twenty-three, a programmer in a small, private software house in Sofia. Vesko didn't turn him in. Even had he wanted to, there was little point: writing viruses is not illegal in Bulgaria. Chapter 6 HACKING FOR PROFIT Inevitably there are people in the computer underworld who use their skills to make money--legally or illegally. Hacking into suppliers to steal goods, or looting credit card companies, has become established practice. But there seems to be little commercial potential in viruses--unless it becomes part of a scam. In December 1989 the first such scam appeared. The virus was used as a blackmail weapon to frighten computer users into paying for protection. Jim Bates, a free-lance computer ecurity consultant, was one of the first to examine the blackmail demand delivered on an apparently ordinary computer diskette. He had received a call earlier that day from Mark Hamilton, the technical editor of a British computer magazine called PC Business World. Mark had sounded worried: "There's apparently been a trojan diskette sent out to PC Business World customers. We don't know anything about it. If we send you a copy, can you look into it?" Jim runs his little business from his home in a commuter suburb ith the misleadingly bucolic name of Wigston Magna, near ~icester, in the English Midlands. Though he had other work to at the time, he agreed to "look into it"- -which meant, effecvely, disassembling the bug. It would be a time-consuming task. ~"What does it do?" he asked. "We don't know. It may be some sort of blackmail attempt." 142 APPROACHING ZERO To Jim, the concept of viral blackmail sounded unlikely. As far as he knew, no one had ever made a penny out of writing virUses. It was said that if there was any money in writing bugs, Bulgaria would be one of the richest countries in Europe; but instead it remained one of the poorest. At 5:30 that afternoon, December 12,1989, the package from PC Business World arrived. As promised, it contained a diskette, of the sort sent out to the magazine's readers; it also contained a copy of a blue instruction leaflet that had accompanied the diskette. Jim examined the leaflet closely. "Read this license agreement carefully [and] if you do not agree with the terms and conditions . . . do not use the software," it began. It then stated that the program on the diskette was leased to operators for either 365 uses at a price of $189, or the lifetime of their hard disk at a price of $389. "PC Cyborg Corporation," it continued, "also reserves the right [sic] to use program mechanisms to ensure termination of the use of the program [which] will adversely affect other program applications." So far, Jim thought, it read much like a normal software licensing agreement, except for the warning that the program might "adversely effect other program applications." But farther down in the small print on the leaflet was a paragraph that made him sit up. "You are advised of the most serious consequences of your failure to abide by the terms of this agreement: your conscience may haunt you for the rest of your life . . . and your computer will stop functioning normally [authors' italics]." This, Jim thought, was carrying the concept of a licensing agreement too far. Licensing software was a perfectly acceptable business practice, as was making threats that unauthorized users of their products would be prosecuted for "copyright infringement." They never threatened to punish unauthorized users by damaging their computers. Even more unusual, the diskette had been sent out like junk mail, unrequested, to computer users around Great Britain, inviting them to run it on their machines. Whoever had distributed the diskettes had obviously purchased PC Business World's mailing list, which the magazine routinely rented out in the form of addressed labels. The magazine had seeded its list with names and addresses of its own staff, an ordinary practice that allows the renter to check that its clients aren't using the list more often than agreed. These seeded addresses had alerted the magazine to the existence of the diskette. If the publication had received copies from its seeded addresses, so had some seven thousand others on the mailing list. And Jim knew that many of these would have loaded the program without reading the blue leaflet--which was, in any case, printed in type so small that it was almost unreadable. Anyone who had already run the diskette, Jim thought, could well be sitting on a time bomb. Later that evening an increasingly anxious Mark Hamilton phoned again: "We're now getting reports that this disk has been found in Belgium, Paris, Germany, Switzerland, Scandinavia, and Italy. Can you do anything with it?" In fact, Jim was already working on an antidote. He had loaded the diskette on an isolated test computer in his upstairs office and had discovered that it contained two very large executable files: an "Install" program and an "AIDS" program. Jim had previously attempted to run the AIDS file on its own, but after a few seconds it aborted, displaying the message: "You must run the Install program before you can use the AIDS program." He followed the instructions, warily loading up Install. It beeped into life, the light on the hard disk flickering off and on. When the installation was finished, Jim looked at the hard disk, using software designed to see all of the files listed in the computer's various directories. The software also allowed him to see any "hidden" files, those generally concealed from casual inspection to prevent them being deleted accidentally. There are always two hidden operating system files on a hard disk; but now, after running the Install program, there was suddenly a whole series of them, none of them named. He decided to have a look at the hidden files, using another 144 APPROACHING ZERO special program. This software went right into the heart of the files, penetrating the binary code, the building blocks of programs. It presented the contents on a vertically split screen: the left side displaying the files in computer code, the right in ordinary text. Jim went through them page by page. He discovered that the hidden files contained a counter, which kept track of the number of times the computer was turned on. After ninety start-ups the hidden files would spring to life and attack the computer's hard disk, encrypting working files and hiding programs.' Without access to programs and data, the system would be unusable. The diskette Jim realized, was a huge trojan horse, a malicious piece of software that entered a system in the guise of something useful, then unleashed its payload. In this case the "useful" component was the "AIDS information" file; the payload was the scrambling of the hard disk. Curiously, Jim found that the program had been written to behave almost like the real AIDS virus. It was opportunistic, just like its biological counterpart; it spread its infection slowly; and was ultimately fatal to its hosts. Whoever wrote the program must have been casually interested in AIDS, though perhaps he didn't know a great deal about the subject. Switching to the AIDS information file, Jim read through the material it offered, which described itself as "An interactive program for health education on the disease called AIDS.... The health information provided could save your life.... Please share this program diskette with other people so that they can benefit from it too." The program offered "up-to-date information about how you can reduce the risk of future infection, based on the details of your own lifestyle and history." It required a user to answer thirtyeight questions--sex, age, number of sexual partners since 1980, medical history, sexual behavior, and so on--and according to the user's answers it provided "confidential advice," most of which was eccentric and misleading: "Scientific studies show that you cannot catch AIDS from insects," and "AIDS can be prevented by avoiding the virus" were two of the less helpful comments. Others included, "Danger: Reduce the number of your sex partners now!" "You are advised that your risk of contracting Al DS is so large that it goes off the chart of probabilities." "Buy condoms today when you leave your office." "Insist that your sex partner be mutually faithful to the relationship." "Casual kissing appears to be safe. Open-mouth kissing appears to be more dangerous. It is that which follows open-mouth kissing that is most risky.'' "The AIDS virus may appear in small quantities in the tears of an infected person." The AIDS trojan, as it had quickly become named, also produced a variety of messages demanding payment for the license. In certain cases, if the computer was linked to a printer, it could cause an invoice to be printed out. The money for the license was to be sent to PC Cyborg Corporation at a post office box in Panama City, Panama. It was not specified what users would receive for the fee, apart from a license. But it was assumed that an antidote for the trojan would be included in the deal. The AIDS information diskette was the largest and most complex trojan Jim had ever seen. He worked on it eighteen hours a day for seventeen days and later said that taking the program apart was "like peeling an onion with a paper clip." His final disassembly ran to 383 pages, each containing 120 lines of code. He had managed to produce a quick antidote to the AIDS trojan on the day he received it, but after he had disassembled the bug, he put together a program called ClearAid which would restore files and cleanse infected systems. The antidote and ClearAid were offered free to infected computer users by Jim and PC Business World. Later, when the furor died down, Jim decided that the trojan had been written "by a young, inexperienced programmer with only scant knowledge of both the language and the machine capabilities at his disposal." Its tortuous complexity had been caused by incompetence rather than design. ' This was little comfort for those who had suffered damage from the bug. Over twenty thousand of the AIDS diskettes had been 146 APPROACHING ZERO sent out, using not only the PC Business World mailing list, but the delegate register to a World Health Organization (WHO) conference on AIDS in Stockholm. In the first few days, a number of recipients had panicked when they realized that they had just loaded a potentially destructive trojan onto their systems. The trojan had caused the loss of data at the U.N. Development Program offices in Geneva, and in Italy an AIDS research center at the University of Bologna reported the loss of ten years of research. Like many users, they had not kept backup copies of their valuable data. The trojan reached hospitals and clinics throughout Europe, and the Chase Manhattan Bank and International Computers Limited (ICL) in England both reported unspecified "problems" caused by the program. In every instance, scientists, researchers, and computer operators wasted days chasing down and eliminating the bug, even after Jim's antidote and ClearAid program became generally available. At New Scotland Yard the Computer Crime Unit under Detective Inspector John Austen established that all twenty thousand diskettes had been posted from west and southwest London, between December 7 and I I, 1989, and that they had been sent to addresses in almost every country of the world, with one glaring exception: none had been sent to the United States. The Computer Crime Unit does not have an easy job. In many cases it has been frustrated by the unusual nature of computer crime, and with viruses it has been noticeably unsuccessful in bringing prosecutions. Most viruses are written abroad, by unknown and certainly untraceable authors, often in countries such as Bulgaria where the act itself is not a criminal offense. To prosecute a case against a virus writer, the unit must have a complaint against the author from a victim in Britain, evidence of criminal intent, proof of the author's identity, and finally, his presence in Britain, or at least in a country from which he can be extradited. The legal problem with viruses, quite simply, is their internationality. They seep across borders, carried anonymously on diskettes or uploaded via phone lines to bulletin boards; their provenance is often unknown, their authorship usually a mystery. But inspectOr John Austen was determined that the AIDS diskette incident would be different. He viewed it as the "most serious" case the unit had faced: not only was it a large-scale attack on computers by a trojan-horse program, it was blackmail--or something very similar. In this case, he also had a complaint; indeed, he had a few thousand complaints. It was clearly time for the unit to throw its resources into tracking down the author of the trojan. The publishers of PC Business World told the police that they had sold this particular mailing list for about $2,000 to a Mr. E. Ketema of Ketema & Associates, who purported to be an African businessman representing a Nigerian software company. The transaction had been carried out by post; no one had ever met Ketema. Ketema & Associates operated out of a maildrop address in Bond Street, London. Company documents revealed that the firm had three other directors, supposedly Nigerian: Kitian Mekonen, Asrat Wakjiri, and Fantu Mekesse. The staff of the company that operated the maildrop had never seen the three Nigerians, but they had met Mr. Ketema. Far from being an African businessman, he was described as white, bearded, and probably American. Computer Unit detectives then turned their attention to PC Cyborg Corporation of Panama City. Through inquiries to the Panamanian police, it was discovered that the company had been registered a year earlier. The Panamanians were also able to find the company's local telephone number. Waiting until early evening in London, when it would be ten A.M. in Panama, a detective put a call through, and was rewarded by the sound of an American voice when the phone was answered. "Mr. Ketema?" asked the detective tentatively. "Who?" answered the voice. It turned out to be an American marine. Panama had been invaded on that very day.2 - Simultaneous inquiries in Nigeria did not turn up evidence of 148 APPROACHING ZERO the three Nigerian businessmen who were registered as directors of the company. Indeed, the Unit discovered that the three names didn't sound Nigerian at all. They might have been made up. By then the Computer Unit's detectives were convinced that they were chasing one man, probably an American. The arrest happened almost by accident. New Scotland Yard had routinely circulated details of the case to Interpol, the international police intelligence agency. Four days before Christmas in 1989, just two weeks after the diskettes had been posted from London, the Dutch police detained an American citizen at Schiphol airport in Amsterdam, who had been behaving strangely. The American was Joseph Lewis Popp. He was en route from Nairobi, where he had been attending a WHO seminar, to Ohio, where he lived with his parents in the small town of Willowick, near Cleveland. Popp seemed to think that someone was trying to kill him: at Schiphol he had written "Dr. Popp has been poisoned" on the suitcase of another traveler, apparently in an attempt to notify the police. When he had calmed down, the authorities took a discreet look through his bags: in one, they found the company seal for PC Cyborg Corporation. The police let Popp continue his journey to Ohio, then notified Austen in England about the seal. On January 18, 1990, Austen began extradition proceedings. The charge: "That on December 11, 1989, within the jurisdiction of the Central Criminal Court, you with a view to gain for another, viz. PC Cyborg Corporation of Panama, with menaces made unwarranted demands, viz. a payment of one hundred and eighty nine U.S. dollars or three hundred and seventy eight U.S. dollars from the victim." In Ohio the FBI began a surveillance of Popp's parents' home, and finally arrested him on February 3rd. Neighbors in Willowick were said to have been surprised at his arrest. He was described as "quiet, intelligent, and a real gentleman." At the time of his arrest he was thirty-nine, a zoologist and anthropologist who had worked as a consultant on animal behavior with UNICEF and WHO. He was a soft-spoken man, darkhaired, with flecks of gray in his beard. He had graduated from Ohio State University in 1972 and obtained a doctorate in anthropology from Harvard in 1979. In the previous few years he had become passionately interested in AIDS. Austen's extradition request ground through the American courts for nearly a year. In September 1990 Jim Bates was flown over to Cleveland for five days to give evidence at Popp's extradition hearing. It is unusual to have live witnesses at such hearings, but Jim brought the AIDS diskette. He was the principal witness, and it was his task to demonstrate to the court what the diskette was and what it did. In the hallway outside the small courtroom, Jim sat beside Popp's parents, a friendly and courteous pair. "Do you like Cleveland?" Popp's mother asked. Jim wasn't sure; all he had seen by then was the airport, a hotel room, and the hallway. Inside the courtroom Jim had his first glance at Joseph Popp. His hair was long and unkempt, his beard had grown out, making the ~ray more emphatic. He shuffled around the courtroom, wearing ~a shabby jacket, a sweater, and faded jeans. He looked, Jim later ~aid, "like a lost soul." Popp's mental state was the crux of the defense's argument in the extradition hearings: his lawyers argued that he had suffered a nervous breakdown and was unfit to stand trial. Popp never denied writing the AIDS trojan nor sending out the diskettes. But at the time, his lawyers said, he was in the grip of mental illness and was behaving abnormally. The lawyers also argued that the demand for a license fee for the use of the diskette was not tantamount to blackmail. It was, they agreed, somewhat extreme to wreck a computer's hard disk if the user didn't pay, but operators were warned not to load the diskette if they didn't accept the terms and conditions laid down in the instruction leaflet. And it was quite clearly stated on the same sheet that if they used the diskette and didn't pay, the computer "would stop functioning normally." There was a basis in law to the argument. Software publishers 150 APPROACHING ZERO have long struggled to stop the unauthorized use and copying of their copyright programs. Software piracy is said to cost Ameri can publishers as much as $5 billion a year, and many markets Taiwan, Thailand, Hong Kong, Singapore, Brazil, India, and even Japan, among others--have become what are euphemistically referred to as "single-disk" countries: in other words, countries where one legitimate copy of a software program is bought and the rest illegally copied. To combat piracy, publishing houses have used a number of devices: some programs, for example, contain deliberate "errors," which are triggered at set intervals--say, once every year--and which require a call from the user to the publisher to rectify. The publisher can then verify that the user is legitimate and has paid his license fee before telling him how to fix it. Other publishers have resorted to more extreme methods. One celebrated case involved an American cosmetics conglomerate that had leased a program from a small software house to handle the distribution of its products. On October 16, 1990, after a disagreement between the two about the lease payments, the soft- ware company dialed into the cosmetic giant's computer and entered a code that disabled its own program. The cosmetics company's entire distribution operation was halted for three days. The software house argued that it was simply protecting its property and that its action was akin to a disconnection by the telephone company. The cosmetics company said that it was "commercial terrorism." The Cleveland District Court, however, rejected arguments that the AIDS diskettes simply contained some sort of elaborate copyright-protection device. It also ruled that Popp was fit to stand trial and ordered his extradition to Britain to face charges. Popp was the first person ever extradited for a computer crime and the first ever to be tried in Britain for writing a malicious program. From the welter of complaints, the police had prepared five counts against him; he faced ten years in prison on each charge. According to the police, Popp had perpetrated a scam that could have grossed him over $7.5 million, assuming that each of the twenty thousand recipients of the diskette had sent the "lifetime" license fee. More realistically, it was estimated that one thousand recipients had actually loaded the diskette after receiving it; but even if only those one thousand had sent him the minimum license fee, he still would have earned $189,000. The police also discovered a diskette that they believed Popp intended to send out to "registered users" who had opted for the cheaper, $189 license. Far from being an antidote, it was another trojan and merely extended the counter from 90 boot-ups to 365 before scrambling the hard disk. In addition, there was evidence that the London mailing was only an initial test run: when Popp's home in Ohio was raided, the FBI found one million blank diskettes. It was believed that Popp was intending to use the proceeds from the AIDS scheme to fund a mass, worldwide mailing, using another trojan. The potential return from one million diskettes is a rather improbable $378 million. The police also had suspicions that Popp, far from being mentally unstable, had launched the scheme with cunning and foresight. For example, he had purposely avoided sending any of the diskettes to addresses in the United States, where he lived, possibly believing that it would make him immune to prosecution under American law. But the case was never to come to trial. Popp's defense presented evidence that his mental state had deteriorated. Their client, his British lawyers said, had begun putting curlers in his beard and wearing a cardboard box on his head to protect himself from radiation. In November 1991 the prosecution accepted that Popp was mentally unfit to stand trial. To this day, the Computer Crime Unit has never successfully prosecuted a virus writer.3 For Popp, whatever his motives and his mental state, the AIDS scheme was an expensive affair--all funded from his own pocket. The postage needed to send out the first twenty thousand diskettes had cost nearly $7,700, the envelopes and labels about $11,500, the diskettes and the blue printed instruction leaflets yet 152 APPROACHING ZERO another $11,500--to say nothing of the cost of registering PC Cyborg Corporation in Panama, or establishing an address in London. To add insult to injury, not one license payment was ever received from anyone, anywhere. Popp's scheme was not particularly well thought out. The scam depended on recipients of his diskettes mailing checks halfway around the world in the hope of receiving an antidote to the trojan. But, as John Austen said, "Who in their right mind would send money to a post office box number in Panama City for an antidote that might never arrive?" Or that may not be an antidote anyway. It seems unlikely that anyone will ever again attempt a mass blackmail of this type; it's not the sort of crime that lends itself to a high volume, low cost formula. It's far more likely that specific corporations will be singled out for targeted attacks. Individually, they are far more vulnerable to blackmail, particularly if the plotters are aided by an insider with knowledge of any loopholes. An added advantage for the perpetrators is the likely publicity blackout with which the corporate victim would immediately shroud the affair: every major corporation has its regular quota of threats, mostly empty, and a well-defined response strategy. But at present, hacking--which gives access to information--has proven to be substantially more lucrative. Present-day hackers traffic in what the authorities call access device codes, the collective name for credit card numbers, telephone authorization codes, and computer passwords. They are defined as any card, code, account number, or "means of account access" that can be used to obtain money, goods, or services. In the United States the codes are traded through a number of telecom devices, principally voice-mail computers; internationally, they are swapped on hacker boards. The existence of this international traffic has created what one press report referred to colorfully as "offshore data havens"--pirate boards where hackers from different countries convene to trade Visa numbers for computer passwords, or American Express accounts for telephone codes. The passwords and telephone codes, the common currency of hacking, are traded to enable hackers to maintain their lifeline--the phone--and to break into computers. Credit card numbers are used more conventionally: to fraudulently acquire money, goods, and services. The acquisition of stolen numbers by hacking into credit agency computers or by means as mundane as dumpster diving (scavenging rubbish in search of the carbons from credit card receipts) differs from ordinary theft. When a person is mugged, for example, he knows his cards have been stolen and cancels them. But if the numbers were acquired without the victim knowing about it, the cards generally remain "live" until the next bill is sent out, which could be a month away. Live cards--ones that haven't been canceled and that still have 60me credit on them--are a valuable commodity in the computer underworld. Most obviously, they can be used to buy goods over the phone, with the purchases delivered to a temporary address or an abandoned house to which the hacker has access. The extent of fraud of this sort is difficult to quantify. In April 1989 Computerworld magazine estimated that computer-related crime costs American companies as much as $555,464,000 each year, not including lost man-hours and computer downtime. The figure is global, in that it takes in everything: fraud, loss of data, theft of software, theft of telephone services, and so on. Though it's difficult to accept the number as anything more than a rough estimate, its apparent precision has given the figure a spurious legitimacy. The same number frequently appears in most surveys of computer crime in the United States and is even in many government documents. The blunt truth is that no one can be certain what computer fraud of any sort really costs. All anyone knows is that it occurs.