In 1999, David L. Smith released the macro virus known as W97M/Melissa.A@mm,
aka the Melissa virus. This virus infected thousands of computers that utilized
Microsoft Outlook. The virus was spread through email with a word attachment.
The email had a format that looked like the text below. (We Live
Security, 2016)
The document used a name of an exotic dancer, which Smith
says was a bit of social engineering to get people to open the attachment. Once
the user had downloaded the attachment and opened it, the virus went to work. It
disabled the program’s macro security, slowed the processes of Outlook
significantly, infected documents on the machine, and then sent itself to up to
50 addresses in the users email address list. Using these addresses, it would
send itself to new victims under the guise of the previous victim. This got more
people to open the attachment since it was from someone they trusted. (We Live
Security, 2016)
The damage caused by the virus were more substantial than
expected. Damages and loss of productivity brought the total costs to be around
80 million dollars. The FBI believes that this could have been substantially
higher if Smith was not apprehended. At his trial, Smith admitted that he was
not aware that the virus would spread so quickly or cause so much damage. He
initially intended for the virus to be a practical joke. Smith pleaded guilty,
sentenced to 20 months in prison, fined $5,000, and ordered to “not be involved
with computer networks, the internet, or internet bulletin boards unless
authorized by the court”. (We Live
Security, 2016)
We Live Security. (2016, July 15). Flashback
Friday: The Melissa Virus. Retrieved from We Live Security:
https://www.welivesecurity.com/2016/07/15/flashback-friday-melissa-virus/
Comments
Post a Comment