WORKING NOTES / 26 SEP 2026

Research Notes.

Source log, comparisons, and open questions for the 1989 virus response case study.

1989 Virus Response: Then and Now

Research question

How much of modern malware response was already understood in 1989, and where did the Soviet KGB's guidance differ from current practice?

Sources and provenance

SourceRoleDetails
Resolution of the President of the USSR KGB on the procurement and use of a foreign software toolPrimary sourceDated 28 July 1989. Lithuanian archive reference F. K-51, ap. 3, b. 58, l. 70–74. The ten-page Russian scan was reviewed for this project as KGB RESEARCH.pdf. PDF pages 1–2 are the directive; pages 3–10 are its eight-page advisory. Archive record.
Oleg Shakirov, How the KGB Discovered Computer Viruses, 2 February 2026Secondary analysis and selected translationThe author summarizes the scan, translates excerpts, adds context from other sources, and identifies uncertainties. Do not treat all contextual claims as direct statements in the 1989 document.

Evidence log — first pass

Page numbers below are PDF page numbers, not handwritten archive folio numbers. These are concise paraphrases from the scanned Russian; exact translations require a careful transcription and review.

IDClaim supported by the primary sourcePDF pageStatus / qualification
E01The directive is dated 28 July 1989 and addresses acquisition, use, and copying of foreign software.1Directly visible in heading and date.
E02It orders use of authorized software and adherence to the attached computer-virus advisory.2Directly visible in numbered instructions.
E03The advisory reports computer-virus incidents in Soviet organizations, including KGB departments, during 1987–1989.4Report made by the document; incident counts and identities need independent corroboration.
E04It describes several known virus types and says the KGB had detection/removal programs for two of them.6–7The exact identity and size of the third type require checking against independent sources.
E05On suspicion of infection, it advises suspending work on the affected computer and other computers with which information may have been exchanged.9Directly visible in response section; translation is a paraphrase.
E06It advises starting from a trusted, write-protected reference copy of the operating system, checking programs for known viruses, and comparing affected programs with reference copies.9Directly visible in response section; translation is a paraphrase.
E07It recommends restoring affected programs from reference copies rather than continuing to use a copy after removing the virus.9Directly visible in response section; translation is a paraphrase.

MacBook lab 01 — trusted copy and file integrity

Purpose. Demonstrate a modern analogue of the document's comparison against a trusted reference. This is a harmless text-file exercise; it does not simulate malware infection. SHA-256 was not the technique prescribed in the 1989 document.

Lab setup. On a 2019 Intel MacBook Pro, created ~/Desktop/KGB-1989-Lab/program.txt containing Approved version and recorded its SHA-256 digest with shasum -a 256. Copied it to reference.txt, then replaced only program.txt with Changed version.

Observed result. The two files produced different SHA-256 digests. diff -u showed one removed line (-Approved version) and one added line (+Changed version). The reference file retained the original digest. These observations were documented in Terminal screenshots on 26 September 2026.

Interpretation. A digest comparison establishes that the bytes differ, assuming the reference digest and file are trusted. The line comparison explains the visible content change. Neither result alone establishes a malicious cause. In a real investigation, first establish provenance and preserve evidence before changing or restoring files.

Virus descriptions — source comparison

The 1989 advisory describes three types it says were known in the USSR. The names below for the first and third cases come from later identification; the scan often uses size and behavior instead of a stable family name.

Description in the 1989 advisoryLater comparisonAssessment
A 648-byte virus also called DOS-62, TIMEBOMB, or VHS-648 that affects .COM files (PDF p. 6).Vienna is listed as a 648-byte .COM file virus in Virus Bulletin (January 1991, PDF); F-Secure has a Vienna description.Strong identification as Vienna or a Vienna variant. The memo's report of circulation in Soviet organizations is a separate historical claim.
A 1701-byte type makes characters fall on the display (PDF p. 7).F-Secure describes Cascade, including a 1701-byte variant and the falling-character effect.Strong identification as Cascade.
A 710-byte type destroys programs launched on Friday the 13th (PDF p. 7). The scan does not clearly name it Jerusalem.F-Secure describes Jerusalem as activating on Friday the 13th, but describes the small Einstein variant as 878 bytes. Shakirov calls the identification probable and flags the size discrepancy.Unresolved: behavior resembles Jerusalem; the 710-byte figure does not match the cited variant size. Do not label this definitively.

The comparison sources document families and behavior; they do not independently prove when or where each infection in the memo occurred.

Incident response: 1989 memo and current guidance

Modern comparison source: NIST, SP 800-61 Revision 3, final 3 April 2025. This revision uses the CSF 2.0 Functions and gives organizational guidance. It does not prescribe one universal command sequence for every computer.

Response concern1989 memo (PDF page 9)NIST SP 800-61r3 (PDF page)Assessment
Prevent spreadSuspend work on the suspected PC and computers that exchanged information with it.Containment prevents expansion; actions can include quarantining malware or moving an endpoint to an isolated network (p. 39).Same broad goal; scope and technology differ.
Determine what happenedCheck suspected programs with available detectors and compare with trusted reference copies.Triage and validate reports, establish the sequence of events and root cause, and document affected assets (pp. 34–36).Both investigate, but NIST expresses wider scope and explicit prioritization.
Restore safelyUse a write-protected reference OS copy; replace affected programs from clean references rather than reuse a disinfected copy.Verify restoration assets before use and verify restored assets before returning them to operation (p. 41).Shared concern for trusted recovery material; NIST allows recovery choices based on scope and resources.
Communicate and learnThe memo instructs reporting suspected cases to a central technical institute (PDF p. 10; translation to be reviewed).Coordinate notifications and communications, document the response, and feed lessons learned into improvements (pp. 12–13, 41–42).The presence of reporting is comparable; institutional structure and feedback loop differ.

Limit of comparison. The memo is an internal Soviet directive addressing virus threats in its 1989 computing environment. NIST is a modern, general organizational framework. Similar words do not prove identical capabilities, effectiveness, or motives.

Working timeline

The labels distinguish a historical document's assertion from a later author's added account. An event reported by the KGB is evidence of what the KGB stated in 1989, not independent proof of every underlying incident.

DateEvent or claimEvidence class and locationLimit
1982A factory software sabotage incident is invoked as background.Retrospective account in 1989 advisory, PDF p. 3; Shakirov adds context.This was deliberate program alteration, not shown to be a self-replicating virus. Details need separate archival corroboration.
From 1985The advisory says reports of computer viruses appeared in foreign publications.1989 advisory, PDF p. 4.A retrospective generalization, not a catalog of individual reports.
1987–1989The advisory says virus incidents became more frequent in Soviet computing centers and KGB departments.1989 advisory, PDF p. 4.Locations and numbers are the memo's report.
August–November 1988Shakirov describes Vienna's Soviet detection and the first AIDStest release.Shakirov's 2026 analysis, with separate sources linked there.Not dates established by the uploaded ten-page scan; verify from contemporaneous records before treating them as settled.
29 June 1989The advisory refers to earlier technical guidance on finding known viruses.1989 advisory, PDF p. 9.We have not obtained the referenced June guidance itself.
28 July 1989KGB directive to use authorized software and the attached virus advisory.Primary-source scan, PDF pp. 1–2; archive catalog.Document date is directly visible.
3 April 2025NIST published SP 800-61 Revision 3.NIST final publication.A comparison benchmark, not part of the 1989 history.
2 February 2026Oleg Shakirov published his selected translation and analysis.Author's article.Secondary interpretation.

Next work

  1. Transcribe and review the incident-response passage on PDF page 9 in detail.
  2. Find contemporaneous corroboration for the 1988 Vienna/AIDStest dates and retain the 710-byte identification as an open question.
  3. Review the page-10 reporting passage closely and refine the comparison with NIST's communications and improvement sections.
  4. Keep all hands-on demonstrations on benign files on the user's MacBook.