AIDS (Trojan horse)

Last reviewed:

AIDS, also known as the AIDS Trojan or AIDS Information Diskette, is one of the earliest examples of ransomware. Released in 1989, it was distributed via floppy disks and targeted users by encrypting files on their computers, demanding a ransom to restore access. The AIDS Trojan is notable for its historical significance as it marked the beginning of ransomware as a cyber threat. Unlike modern ransomware, which often uses sophisticated encryption methods and widespread distribution tactics, the AIDS Trojan was relatively simple in its design and execution.

Overview

The AIDS Trojan, also referred to as the AIDS Information Diskette, is recognized as the first known instance of ransomware. It was created by Dr. Joseph Popp, a biologist, and distributed in December 1989. The Trojan was spread through physical floppy disks sent to attendees of the World Health Organization's AIDS conference. Once installed, the malware encrypted file names on the infected computer and demanded a ransom for decryption. This early form of ransomware highlighted the potential for malware to be used for financial gain, setting a precedent for future cybercriminal activities.

History

The AIDS Trojan emerged in the late 1980s, a time when personal computers were becoming more common in homes and offices. Dr. Joseph Popp, who was reportedly motivated by a desire to raise awareness about AIDS, distributed the Trojan via 20,000 floppy disks labeled as educational material on AIDS. These disks were mailed to individuals and organizations worldwide. Upon installation, the Trojan would remain dormant for a period before activating and encrypting file names, rendering them inaccessible. The ransom note demanded payment to a post office box in Panama, marking one of the first instances of cyber extortion.

Technical characteristics

The AIDS Trojan was relatively unsophisticated compared to modern ransomware. It operated by altering the file names on the infected system, making them unreadable. The malware used a simple symmetric encryption method, which could be reversed with the correct decryption key. The ransom demand was printed on the screen, instructing victims to send $189 to a post office box in Panama to receive the decryption tool. The simplicity of the encryption allowed for the development of tools to decrypt the files without paying the ransom, which was a significant difference from the more advanced encryption techniques used in contemporary ransomware.

Infection vector

The primary infection vector for the AIDS Trojan was physical distribution via floppy disks. These disks were labeled as containing educational material on AIDS and were mailed to individuals and organizations. This method of distribution was effective at the time due to the widespread use of floppy disks for software installation and data transfer. The Trojan required manual installation by the user, which involved running the program on the disk. Once executed, the malware would install itself on the system and begin its encryption process after a set number of reboots.

Notable campaigns

The AIDS Trojan did not have multiple campaigns in the way modern ransomware does, as it was primarily a single event orchestrated by Dr. Joseph Popp. However, its impact was significant enough to garner attention from law enforcement and cybersecurity professionals. The distribution of the Trojan at a global scale was unprecedented at the time, and it served as a wake-up call to the potential for malware to be used for financial extortion. The incident also highlighted the need for improved cybersecurity measures and awareness among computer users.

Detection and mitigation

Detection of the AIDS Trojan was challenging at the time due to the lack of advanced antivirus software and cybersecurity infrastructure. However, once the nature of the Trojan was understood, cybersecurity experts were able to develop tools to reverse the encryption without paying the ransom. Mitigation involved removing the Trojan from the system and using these decryption tools to restore access to the affected files. The incident underscored the importance of regular backups and the need for users to be cautious when installing software from unknown sources.

Timeline of the AIDS Trojan

Flowchart of AIDS Trojan Infection Process

See also

Sources

Categories: Malware | Incidents
Last updated: September 1, 2026