


Computer viruses once dominated the early internet, spreading through email inboxes and vulnerable systems faster than security teams could possibly react. Today’s threats are a whole lot more advanced (ransomware, supply-chain compromises, zero-click exploits; you get the idea), but the early outbreaks helped shape the cyber defenses we rely on today.
We’ve created an updated, chronological list of the most notorious computer viruses and malware incidents in history, from the early 2000s to the modern era. For each, you’ll find out about what happened, why it mattered, and what the cybersecurity community learned from it.
To add a practitioner’s view, we asked cybersecurity expert Matthias Gsteiger, Security Engineer at Canton of Zurich, to share what some of these incidents still mean for organizations today. His comments are included throughout the article.
A computer virus is a type of malicious software that attaches itself to files or programs and replicates itself without the user’s consent. Once activated, it can spread to other systems, damage files, steal data, or disrupt operations. Viruses typically rely on user actions (like opening a bad email attachment or downloading infected software) to execute and propagate.
If you ask Matthias Gsteiger, “a computer virus today is more than just another application or process. It can dig deep into your operating system, run only in memory, and stay ‘invisible’ to the simple eye. Attackers are experts with deep knowledge of IT, operating systems, and how AV or EDR tools work — so their tools are getting better and better.”
Even with stronger operating systems, better browsers, and cloud-based security, the fundamental entry points for malware haven’t changed a whole lot in recent years. Attackers simply became better at exploiting them.


The most common path remains phishing emails. Threat actors impersonate trusted senders, deliver malicious attachments, or hide malware inside seemingly harmless PDFs or invoices. Because phishing kits automate everything (design, timing, sending, personalization) a lot of victims don’t realize what they’re clicking until it’s already too late.
According to Matthias Gsteiger, “awareness is spreading and that’s great, but attackers’ techniques are getting better and better. It’s not a generic mail in your mailbox anymore — it’s a response to an email flow you had a month ago, in perfect spelling and matching the conversation. That might be the entry door for an attack.”
Another prevalent source is downloading software from unverified websites. Fake installers, cracked software, or bundled toolbars often contain hidden malware. Software acquired outside trusted vendors or official repositories remains one of the highest-risk vectors for individuals and organizations.
A third method is malvertising; malicious ads placed on legitimate websites. Users can become infected simply by loading a page with a compromised ad, even without clicking it. Attackers use this vector because it targets anyone who visits a popular site, making it incredibly efficient for spreading malware at scale.
In every case, attackers rely on the same gap: trust. People trust email senders, websites trust ad networks, and organizations trust software vendors. That trust is what viruses (old and new) continue to exploit.


The “love letter” worm infected approximately 45 million Windows machines in just 10 days. Disguised as a love confession, the attachment overwrote files and forwarded itself to all Outlook contacts.
What it taught us
Klez spread aggressively by spoofing sender addresses and harvesting contacts in Outlook. Constantly changing subject lines made filtering extremely difficult in the early 2000s.
What it taught us
Nimda was the fastest-spreading worm of its time, using multiple infection vectors at once: email, compromised websites, open network shares, and unpatched IIS servers.
What it taught us
Sasser exploited a Windows LSASS vulnerability and spread automatically with no clicks required. Airlines, hospitals, and even government networks went offline.
What it taught us
Conficker infected millions of Windows machines, forming one of the largest botnets ever seen. It exploited a Microsoft vulnerability and disabled security tools to persist.
What it taught us
Shamoon was a destructive wiper that overwrote master boot records, rendering thousands of machines unusable. Saudi Aramco alone lost 30,000 workstations.
What it taught us
Emotet evolved from a banking trojan into the world’s most notorious “malware-as-a-service” botnet. It provided initial access to ransomware gangs and criminal syndicates.
What it taught us
WannaCry infected more than 300,000 machines in 150 countries using the leaked NSA EternalBlue exploit. It heavily impacted hospitals and public services.
What it taught us
NotPetya looked like ransomware but was actually a wiper. Delivered through a Ukrainian software supply chain, it caused an estimated $10 billion in global damage (Wired wrote a great piece on this if you’re curious).
What it taught us
Attackers inserted malicious code into SolarWinds’ Orion updates, compromising U.S. government agencies and major enterprises globally.
What it taught us
Pegasus is a highly advanced mobile spyware toolkit that uses zero-click vulnerabilities to infect iPhones and Android devices silently. It targets journalists, activists, and officials worldwide.
What it taught us
“Potential attackers today are experts. They know operating systems inside out and understand how AV and EDR products work — so they design tools that stay in memory, blend into legitimate processes, and are almost invisible from the outside.” — Matthias Gsteiger, Security Engineer at Canton of Zurich
Volt Typhoon infiltrated U.S. critical infrastructure using “living-off-the-land” techniques: meaning no traditional malware files, only built-in system tools.
What it taught us
“Everyone is talking about ‘zero trust’, but where do you begin ‘trusting no one’? You must go step by step, improve things day by day, and build proper supply chain risk management instead of assuming that vendors and partners are always safe,” says Matthias Gsteiger.
From early email worms to zero-click spyware and supply-chain compromises, malware continues to evolve. But the underlying weakness remains the same: trust, whether in people, software, or systems. Each historic incident helped shape the security practices organizations rely on today.
If you want to protect your company from modern malware threats (through real-world scenarios, practical exercises, and expert-led awareness programs), check out our Team Training offerings at the Swiss Cyber Institute. We’re helping teams stay one step ahead of attackers; and that begins with education rather than fear.
We share the most important news from the industry, technology, and the institute. Stay informed and stay ahead.