# 1989 Virus Response: Then and Now

## Research question

How much of modern malware response was already understood in 1989, and where did the Soviet KGB's guidance differ from current practice?

## Sources and provenance

| Source | Role | Details |
| --- | --- | --- |
| *Resolution of the President of the USSR KGB on the procurement and use of a foreign software tool* | Primary source | Dated 28 July 1989. Lithuanian archive reference F. K-51, ap. 3, b. 58, l. 70–74. The ten-page Russian scan was reviewed for this project as `KGB RESEARCH.pdf`. PDF pages 1–2 are the directive; pages 3–10 are its eight-page advisory. [Archive record](https://www.kgbveikla.lt/dokumentai/1/ssrs-kgb-pirmininko-nutarimas-del-uzsienio-programines-irankos-pirkimo-ir-naudojimo-tvarkos.-7518). |
| Oleg Shakirov, [*How the KGB Discovered Computer Viruses*](https://fromcyberia.substack.com/p/how-the-kgb-discovered-computer-viruses), 2 February 2026 | Secondary analysis and selected translation | The author summarizes the scan, translates excerpts, adds context from other sources, and identifies uncertainties. Do not treat all contextual claims as direct statements in the 1989 document. |

## Evidence log — first pass

Page numbers below are PDF page numbers, not handwritten archive folio numbers. These are concise paraphrases from the scanned Russian; exact translations require a careful transcription and review.

| ID | Claim supported by the primary source | PDF page | Status / qualification |
| --- | --- | --- | --- |
| E01 | The directive is dated 28 July 1989 and addresses acquisition, use, and copying of foreign software. | 1 | Directly visible in heading and date. |
| E02 | It orders use of authorized software and adherence to the attached computer-virus advisory. | 2 | Directly visible in numbered instructions. |
| E03 | The advisory reports computer-virus incidents in Soviet organizations, including KGB departments, during 1987–1989. | 4 | Report made by the document; incident counts and identities need independent corroboration. |
| E04 | It describes several known virus types and says the KGB had detection/removal programs for two of them. | 6–7 | The exact identity and size of the third type require checking against independent sources. |
| E05 | On suspicion of infection, it advises suspending work on the affected computer and other computers with which information may have been exchanged. | 9 | Directly visible in response section; translation is a paraphrase. |
| E06 | It advises starting from a trusted, write-protected reference copy of the operating system, checking programs for known viruses, and comparing affected programs with reference copies. | 9 | Directly visible in response section; translation is a paraphrase. |
| E07 | It recommends restoring affected programs from reference copies rather than continuing to use a copy after removing the virus. | 9 | Directly visible in response section; translation is a paraphrase. |

## MacBook lab 01 — trusted copy and file integrity

**Purpose.** Demonstrate a modern analogue of the document's comparison against a trusted reference. This is a harmless text-file exercise; it does not simulate malware infection. SHA-256 was not the technique prescribed in the 1989 document.

**Lab setup.** On a 2019 Intel MacBook Pro, created `~/Desktop/KGB-1989-Lab/program.txt` containing `Approved version` and recorded its SHA-256 digest with `shasum -a 256`. Copied it to `reference.txt`, then replaced only `program.txt` with `Changed version`.

**Observed result.** The two files produced different SHA-256 digests. `diff -u` showed one removed line (`-Approved version`) and one added line (`+Changed version`). The reference file retained the original digest. These observations were documented in Terminal screenshots on 26 September 2026.

**Interpretation.** A digest comparison establishes that the bytes differ, assuming the reference digest and file are trusted. The line comparison explains the visible content change. Neither result alone establishes a malicious cause. In a real investigation, first establish provenance and preserve evidence before changing or restoring files.

## Virus descriptions — source comparison

The 1989 advisory describes three types it says were known in the USSR. The names below for the first and third cases come from later identification; the scan often uses size and behavior instead of a stable family name.

| Description in the 1989 advisory | Later comparison | Assessment |
| --- | --- | --- |
| A 648-byte virus also called DOS-62, TIMEBOMB, or VHS-648 that affects `.COM` files (PDF p. 6). | Vienna is listed as a 648-byte `.COM` file virus in *Virus Bulletin* (January 1991, [PDF](https://www.virusbulletin.com/uploads/pdf/magazine/1991/199101.pdf)); F-Secure has a [Vienna description](https://www.f-secure.com/v-descs/vienna). | Strong identification as Vienna or a Vienna variant. The memo's report of circulation in Soviet organizations is a separate historical claim. |
| A 1701-byte type makes characters fall on the display (PDF p. 7). | F-Secure describes [Cascade](https://www.f-secure.com/v-descs/cascade), including a 1701-byte variant and the falling-character effect. | Strong identification as Cascade. |
| A 710-byte type destroys programs launched on Friday the 13th (PDF p. 7). The scan does not clearly name it Jerusalem. | F-Secure describes [Jerusalem](https://www.f-secure.com/v-descs/jerusale) as activating on Friday the 13th, but describes the small Einstein variant as 878 bytes. Shakirov calls the identification probable and flags the size discrepancy. | **Unresolved:** behavior resembles Jerusalem; the 710-byte figure does not match the cited variant size. Do not label this definitively. |

The comparison sources document families and behavior; they do not independently prove when or where each infection in the memo occurred.

## Incident response: 1989 memo and current guidance

Modern comparison source: NIST, [SP 800-61 Revision 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final), final 3 April 2025. This revision uses the CSF 2.0 Functions and gives organizational guidance. It does not prescribe one universal command sequence for every computer.

| Response concern | 1989 memo (PDF page 9) | NIST SP 800-61r3 (PDF page) | Assessment |
| --- | --- | --- | --- |
| Prevent spread | Suspend work on the suspected PC and computers that exchanged information with it. | Containment prevents expansion; actions can include quarantining malware or moving an endpoint to an isolated network (p. 39). | Same broad goal; scope and technology differ. |
| Determine what happened | Check suspected programs with available detectors and compare with trusted reference copies. | Triage and validate reports, establish the sequence of events and root cause, and document affected assets (pp. 34–36). | Both investigate, but NIST expresses wider scope and explicit prioritization. |
| Restore safely | Use a write-protected reference OS copy; replace affected programs from clean references rather than reuse a disinfected copy. | Verify restoration assets before use and verify restored assets before returning them to operation (p. 41). | Shared concern for trusted recovery material; NIST allows recovery choices based on scope and resources. |
| Communicate and learn | The memo instructs reporting suspected cases to a central technical institute (PDF p. 10; translation to be reviewed). | Coordinate notifications and communications, document the response, and feed lessons learned into improvements (pp. 12–13, 41–42). | The presence of reporting is comparable; institutional structure and feedback loop differ. |

**Limit of comparison.** The memo is an internal Soviet directive addressing virus threats in its 1989 computing environment. NIST is a modern, general organizational framework. Similar words do not prove identical capabilities, effectiveness, or motives.

## Working timeline

The labels distinguish a historical document's assertion from a later author's added account. An event reported by the KGB is evidence of what the KGB stated in 1989, not independent proof of every underlying incident.

| Date | Event or claim | Evidence class and location | Limit |
| --- | --- | --- | --- |
| 1982 | A factory software sabotage incident is invoked as background. | Retrospective account in 1989 advisory, PDF p. 3; Shakirov adds context. | This was deliberate program alteration, not shown to be a self-replicating virus. Details need separate archival corroboration. |
| From 1985 | The advisory says reports of computer viruses appeared in foreign publications. | 1989 advisory, PDF p. 4. | A retrospective generalization, not a catalog of individual reports. |
| 1987–1989 | The advisory says virus incidents became more frequent in Soviet computing centers and KGB departments. | 1989 advisory, PDF p. 4. | Locations and numbers are the memo's report. |
| August–November 1988 | Shakirov describes Vienna's Soviet detection and the first AIDStest release. | [Shakirov's 2026 analysis](https://fromcyberia.substack.com/p/how-the-kgb-discovered-computer-viruses), with separate sources linked there. | Not dates established by the uploaded ten-page scan; verify from contemporaneous records before treating them as settled. |
| 29 June 1989 | The advisory refers to earlier technical guidance on finding known viruses. | 1989 advisory, PDF p. 9. | We have not obtained the referenced June guidance itself. |
| 28 July 1989 | KGB directive to use authorized software and the attached virus advisory. | Primary-source scan, PDF pp. 1–2; [archive catalog](https://www.kgbveikla.lt/dokumentai/1/ssrs-kgb-pirmininko-nutarimas-del-uzsienio-programines-irankos-pirkimo-ir-naudojimo-tvarkos.-7518). | Document date is directly visible. |
| 3 April 2025 | NIST published SP 800-61 Revision 3. | [NIST final publication](https://csrc.nist.gov/pubs/sp/800/61/r3/final). | A comparison benchmark, not part of the 1989 history. |
| 2 February 2026 | Oleg Shakirov published his selected translation and analysis. | [Author's article](https://fromcyberia.substack.com/p/how-the-kgb-discovered-computer-viruses). | Secondary interpretation. |

## Next work

1. Transcribe and review the incident-response passage on PDF page 9 in detail.
2. Find contemporaneous corroboration for the 1988 Vienna/AIDStest dates and retain the 710-byte identification as an open question.
3. Review the page-10 reporting passage closely and refine the comparison with NIST's communications and improvement sections.
4. Keep all hands-on demonstrations on benign files on the user's MacBook.
