# 1989 Virus Response: Then and Now

## Project overview

I examined a 28 July 1989 Soviet KGB directive and its attached computer-virus advisory, then compared its response guidance with NIST SP 800-61 Revision 3 (2025). I also performed a harmless file-integrity demonstration on my 2019 Intel MacBook Pro. The project asks which incident-response ideas were already recognizable in 1989 and where the historical evidence stops.

**Skills practiced:** primary-source analysis, source attribution, file hashing, `diff`, evidence interpretation, and incident-response comparison.

## Source and method

The primary source is a ten-page Russian scan, cataloged by the Lithuanian archive as F. K-51, ap. 3, b. 58, l. 70–74. Its first two PDF pages contain the directive and the remaining pages contain the advisory. The English descriptions in this project are careful paraphrases, not a certified translation. I kept the document's claims separate from independent verification of the events it reports.

The advisory recommends suspending work when infection is suspected, checking programs against trusted reference copies, and restoring affected programs from clean references (scan p. 9). These broad concerns are recognizable in modern response guidance, although the organizations, tools, and operating environments differ.

## MacBook lab: detect a changed file

This lab used two ordinary text files. It did not use or execute malware. On macOS Terminal I ran:

```sh
mkdir -p "$HOME/Desktop/KGB-1989-Lab"
printf 'Approved version\n' > "$HOME/Desktop/KGB-1989-Lab/program.txt"
shasum -a 256 "$HOME/Desktop/KGB-1989-Lab/program.txt"
cp "$HOME/Desktop/KGB-1989-Lab/program.txt" "$HOME/Desktop/KGB-1989-Lab/reference.txt"
printf 'Changed version\n' > "$HOME/Desktop/KGB-1989-Lab/program.txt"
shasum -a 256 "$HOME/Desktop/KGB-1989-Lab/"*.txt
diff -u "$HOME/Desktop/KGB-1989-Lab/reference.txt" "$HOME/Desktop/KGB-1989-Lab/program.txt"
```

**Observed result:** The SHA-256 digests differed after `program.txt` changed. The unified diff showed `-Approved version` and `+Changed version`. The unchanged `reference.txt` retained the original content.

**Interpretation:** The hash mismatch and diff establish that the files differ and show this particular text change. They do not establish why the change happened or whether it was malicious. A reference is useful only if its origin and integrity are trusted. SHA-256 is a modern demonstration of file integrity; it was not a technique prescribed by the 1989 directive.

## Historical findings

| Description in the advisory | Later comparison | Confidence |
| --- | --- | --- |
| 648-byte `.COM` virus, also labeled DOS-62/TIMEBOMB/VHS-648 (scan p. 6) | Vienna or a Vienna variant | Strong match to later virus descriptions. |
| 1,701-byte virus with falling screen characters (scan p. 7) | Cascade | Strong match to later virus descriptions. |
| 710-byte virus that damages programs launched on Friday the 13th (scan p. 7) | Possibly Jerusalem | Unresolved: the cited Jerusalem variant size differs. |

Those later descriptions help identify virus families; they do not independently verify each Soviet incident reported in the advisory.

## Comparison with current guidance

| Concern | 1989 advisory | NIST SP 800-61r3 (2025) |
| --- | --- | --- |
| Contain | Suspend work on suspected and connected computers. | Limit incident expansion; isolation can be a containment action. |
| Investigate | Test programs and compare them with trusted reference copies. | Validate and prioritize reports; establish events, root cause, and affected assets. |
| Recover | Restore programs from clean references. | Verify restoration assets and recovered systems before use. |

The comparison establishes similarities in response goals, not identical capabilities or proven effectiveness.

## Evidence and limits

- The directive's date and instructions are visible in the primary-source scan. The incident history inside the advisory remains the institution's report until independently corroborated.
- The 710-byte Friday-the-13th virus has not been identified definitively.
- Terminal screenshots recorded the lab result. Before sharing them publicly, I would review them for usernames, paths, or other personal information.

## Sources

1. [Lithuanian archive catalog entry for the 1989 directive](https://www.kgbveikla.lt/dokumentai/1/ssrs-kgb-pirmininko-nutarimas-del-uzsienio-programines-irankos-pirkimo-ir-naudojimo-tvarkos.-7518); ten-page scan supplied for this project as `KGB RESEARCH.pdf`.
2. Oleg Shakirov, [“How the KGB Discovered Computer Viruses”](https://fromcyberia.substack.com/p/how-the-kgb-discovered-computer-viruses), 2 February 2026. Secondary historical analysis and selected translation.
3. NIST, [SP 800-61 Revision 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final), 3 April 2025.
4. F-Secure, virus descriptions for [Vienna](https://www.f-secure.com/v-descs/vienna), [Cascade](https://www.f-secure.com/v-descs/cascade), and [Jerusalem](https://www.f-secure.com/v-descs/jerusale); *Virus Bulletin*, [January 1991 issue](https://www.virusbulletin.com/uploads/pdf/magazine/1991/199101.pdf), Vienna entry.

## Possible follow-up

Transcribe and review the response passage on scan p. 9, then look for contemporary records that independently corroborate the 1988 incidents and clarify the 710-byte virus.
