Dark Avenger

Last updated

Dark Avenger
BornUnknown
Nationality Bulgarian
Occupation(s) Programmer, computer virus writer, computer criminal
Known forWriting computer viruses

Dark Avenger was the pseudonym of a computer virus writer from Sofia, Bulgaria. He gained considerable notoriety during the early 1990s when his viruses spread internationally.

Contents

Background and origins

During the Cold War, the Bulgarian government authorized projects to reverse engineer Western technology. This eventually led to the Pravetz computers of the 1980s, which cloned popular Western personal computers. A community formed around these computers when they were used in schools to teach students computer programming. [1] In April 1988, Bulgaria's trade magazine for computers, Компютър за Вас (Computer for You), published a translation of a German article about computer viruses and methods for writing them. [2] [1] A few months after that, Bulgaria experienced several foreign viruses. The interest spawned by both the article and the viruses inspired young Bulgarian programmers to devise their own viruses. [2] Soon a wave of Bulgarian viruses erupted, started by the "Old Yankee" and "Vacsina" viruses. Dark Avenger made his first appearance in the spring of 1989. [3] At the time, Bulgaria did not have any laws against writing computer viruses. [4] Anti-virus researchers identified Bulgaria as having talented programmers who had few commercial opportunities, [4] and Bulgarian security researcher Vesselin Bontchev blamed the viruses on the country's history of pirating Western computer code and failure to teach students about computer ethics. [5]

Viruses

Dark Avenger's first virus appeared in early 1989 and contained the string, "This program was written in the city of Sofia (C) 1988–89 Dark Avenger". Thus, this first virus is usually referred to as "Dark Avenger", eponymous to its author. [1] Dark Avenger's viruses made frequent references to heavy metal bands, including Iron Maiden, and Diana, Princess of Wales. [4] His pseudonym is based on a Manowar song. [6]

The virus was very infectious: if the virus was active in memory, opening or just copying an executable file was sufficient to infect it. Additionally, the virus also destroyed data, by overwriting a random sector of the disk at every 16th run of an infected program, progressively corrupting files and directories on the disk. [1] Corrupted files contained the string, "Eddie lives... somewhere in time!", [1] a reference to Iron Maiden. [6] Due to its highly infectious nature, the virus spread worldwide, reaching Western Europe, the USSR, the United States, and East Asia. [3]

Dutch author Harry Mulisch reported encountering the virus on his laptop while writing The Discovery of Heaven . Mulisch considered it a "favourable sign from higher powers" and briefly considered naming his son Eduard after the virus' output. [7] A few weeks later, he re-encountered the virus and had it professionally removed. [8]

This virus was soon followed by others, each employing a new trick. Dark Avenger is believed to have authored the following viruses: Dark Avenger, V2000 (two variants), V2100 (two variants), 651, Diamond (two variants), Nomenklatura, 512 (six variants), 800, 1226, Proud, Evil, Phoenix, Anthrax, and Leech. As a major means for spreading the source code of his viruses, Dark Avenger used the then popular bulletin board systems. [9] In its variants, the virus also contained the following strings:

In technical terms, the most prominent feature of some of Dark Avenger's viruses was their Mutation Engine (MtE). This allowed the viruses to change their signature, preventing them from being easily recognized by anti-virus programs. [10] Following its release, Paul Mungo and Bryan Clough called MtE "the most dangerous virus ever produced", [4] and Steve Gibson wrote that "the game is forever changed". [11]

Identity

The identity of the person behind the pseudonym has never been ascertained. [10] In 1992, Dark Avenger described himself as a heavy metal fan under 30 who wrote viruses while procrastinating at his job. [5] Sarah Gordon, a computer security researcher, publicly requested that a virus be named after her. When this request was granted, she used this as an opening to make contact with Dark Avenger. She later published their communications in interview format. [1] Analysis by the researchers Andrew Bissett and Geraldine Shipton concluded that Dark Avenger engaged in victim blaming; he blamed "human stupidity" for the transmission of his viruses and denied that any data of value would be lost on personal computers. They cited his envy of wealthy Westerners' computers as his motivation for making viruses; [12] Gordon herself attributed his motivation to a hatred of Bontchev. [1] Dark Avenger made frequent attacks on Bontchev. Such is the case with the viruses V2000 and V2100, which claim to have been written by Bontchev, to defame him. [9] This conflict between the two has led some to believe that Bontchev and Dark Avenger were promoting each other or that they might be the same person. Bontchev denied this and claimed in 1993 to have deduced Dark Avenger's identity. He said that because writing viruses was not illegal, there was no point in pursuing it. [13]

Dark Avenger's profile was raised substantially by a 1997 story in Wired , in which the journalist David S. Bennahum attempted to track down Dark Avenger. [14] Bennahum did not uncover Dark Avenger's identity but came to suspect the operator of a Bulgarian bulletin board system that collected computer viruses in the 1990s. Neither he nor someone who claimed to be Dark Avenger would say whether this was true. [1]

Related Research Articles

<span class="mw-page-title-main">Cyrillic script</span> Writing system used for various Eurasian languages

The Cyrillic script, Slavonic script or simply Slavic script is a writing system used for various languages across Eurasia. It is the designated national script in various Slavic, Turkic, Mongolic, Uralic, Caucasian and Iranic-speaking countries in Southeastern Europe, Eastern Europe, the Caucasus, Central Asia, North Asia, and East Asia, and used by many other minority languages.

A pseudonym or alias is a fictitious name that a person assumes for a particular purpose, which differs from their original or true name (orthonym). This also differs from a new name that entirely or legally replaces an individual's own. Many pseudonym holders use pseudonyms because they wish to remain anonymous, but anonymity is difficult to achieve and often fraught with legal issues.

<span class="mw-page-title-main">Antivirus software</span> Computer software to defend against malicious computer viruses

Antivirus software, also known as anti-malware, is a computer program used to prevent, detect, and remove malware.

<span class="mw-page-title-main">CIH (computer virus)</span> Windows 9x computer virus

CIH, also known as Chernobyl or Spacefiller, is a Microsoft Windows 9x computer virus that first emerged in 1998. Its payload is highly destructive to vulnerable systems, overwriting critical information on infected system drives and, in some cases, destroying the system BIOS. The virus was created by Chen Ing-hau, a student at Tatung University in Taiwan. It was believed to have infected sixty million computers internationally, resulting in an estimated NT$1 billion (US$35,801,231.56) in commercial damages.

<span class="mw-page-title-main">Ron Goulart</span> American historian (1933–2022)

Ronald Joseph Goulart ( ) was an American popular culture historian and mystery, fantasy and science fiction author.

<span class="mw-page-title-main">Hank Pym</span> Comic book superhero

Dr. Henry Jonathan "Hank" Pym is a character appearing in American comic books, published by Marvel Comics. Created by penciller Jack Kirby, editor-plotter Stan Lee and writer Larry Lieber, Pym debuted in Tales to Astonish #27. He returned several issues later as the original iteration of Ant-Man, a superhero with the power to shrink to the size of an ant. He later assumed other superhero identities, including the size-changing Giant-Man and Goliath; the insect-themed Yellowjacket; and briefly, the Wasp. He is a founding member of the Avengers superhero team, and the creator of the robotic villain Ultron. He is also the ex-husband of Janet van Dyne and the father of Nadia van Dyne, his daughter by his first wife, Maria Pym.

<span class="mw-page-title-main">Red Guardian</span> Marvel Comics character

The Red Guardian is the name of several fictional characters appearing in American comic books published by Marvel Comics: Aleksey Lebedev, Alexei Shostakov, Tania Belinsky, Josef Petkus, Krassno Granitsky, Anton Ivanov, and Nikolai Krylenko, as well as a villainous Life Model Decoy of Shostakov. The Red Guardian is an identity that was created as the Soviet equivalent of Captain America, although its use has continued after the dissolution of the Soviet Union. In the continuity of Ultimate Marvel, the Red Guardian is adapted as two separate characters: Captain Russia and Colonel Abdul al-Rahma.

<span class="mw-page-title-main">Whilce Portacio</span> Comic artist

William "Whilce" Portacio is a Filipino American comic book writer and artist noted for his work on such titles as The Punisher, X-Factor, Uncanny X-Men, Iron Man, Wetworks and Spawn. Portacio was also one of the seven co-founders of Image Comics, though he did not become a full-partner in the company, and is therefore not a member of its board of directors.

<span class="mw-page-title-main">RGD-5</span> Soviet anti-personnel fragmentation grenade

The RGD-5 is a post–World War II Soviet anti-personnel fragmentation grenade, designed in the early 1950s. The RGD-5 was accepted into service with the Soviet Army in 1954. It was widely exported, and is still in service with many armies in the Middle East and the former Soviet bloc.

<span class="mw-page-title-main">John Russell Fearn</span> British writer

John Russell Fearn was a British writer, one of the first to appear in American pulp science fiction magazines. A prolific author, he published his novels also as Vargo Statten and with various pseudonyms including Thornton Ayre, Polton Cross, Geoffrey Armstrong, John Cotton, Dennis Clive, Ephriam Winiki, Astron Del Martia.

FRISK Software International was an Icelandic software company that developed F-Prot antivirus and F-Prot AVES antivirus and anti-spam service. The company was founded in 1993. It was acquired by Cyren in 2012.

<i>The Assault</i> Novel by Harry Mulisch

The Assault is a 1982 novel by Dutch author Harry Mulisch. Random House published an English translation by Claire Nicolas White in 1985. It covers 35 years in the life of the lone survivor of a night in Haarlem during World War II when the Nazi occupation forces, finding a Dutch collaborator murdered, retaliate by killing most of the family in front of whose home the body was found. According to the New York Times, this novel "made his reputation at home and abroad". It was translated into dozens of languages and immediately adapted into a film of the same name that won the 1986 Academy Award for Best Foreign Language Film.

<span class="mw-page-title-main">Sentry (Robert Reynolds)</span> Marvel Comics fictional character

Sentry is a superhero appearing in American comic books published by Marvel Comics. Created by Paul Jenkins and Jae Lee, with uncredited conceptual contributions by Rick Veitch, the character first appeared in The Sentry #1.

<span class="mw-page-title-main">Lyuli</span> Branch of Ghorbati people

The Lyuli, Jughi or Jugi are a branch of the Ghorbati people living in Central Asia, primarily Tajikistan, Uzbekistan, Turkmenistan, Kazakhstan, and southern Kyrgyzstan; also, related groups can be found in Turkey, and the Balkans, Crimea, Southern Russia and Afghanistan. They speak ethnolects of the Persian and Turkic language and practice Sunni Islam. The terms Lyuli and Jugi are considered pejorative. They have a clan organization. Division into sub-clans is also practiced. The Lyuli community is extremely closed towards non-Lyuli.

<i>Batman: Digital Justice</i>

Batman: Digital Justice is a graphic novel published by DC Comics in 1990 in both hardback and paperback forms. It was written and illustrated by Pepe Moreno entirely using computer hardware, software and techniques. The story takes place outside regular DC continuity, but is not an Elseworlds title.

<span class="mw-page-title-main">Norman Osborn</span> Marvel Comics fictional character

Norman Virgil Osborn is a fictional character appearing in American comic books published by Marvel Comics. The character, created by writer Stan Lee and artist Steve Ditko, first appeared in The Amazing Spider-Man #14 as the first and best-known incarnation of the Green Goblin. He has endured as one of Spider-Man's most prominent villains, and is regarded as one of his three archenemies, alongside Doctor Octopus and Venom.

<span class="mw-page-title-main">Green Goblin in other media</span> Appearances of Green Goblin in cinema, television and video games

The Green Goblin, a Marvel Comics supervillain and one of the archenemies of Spider-Man, alongside Doctor Octopus and Venom, was created by Stan Lee and Steve Ditko and first appeared in The Amazing Spider-Man #14. The character has since been substantially adapted from the comics into various forms of media, such as feature films, television series and video games.

Anna Kournikova was a computer virus that spread worldwide on the Internet in February 2001. The virus program was contained in an email attachment, purportedly an image of tennis player Anna Kournikova.

<span class="mw-page-title-main">Operation INFEKTION</span> KGB disinformation campaign claiming that HIV was a U.S. bioweapon

Operation Denver was an active measure disinformation campaign run by the KGB in the 1980s to plant the idea that the United States had invented HIV/AIDS as part of a biological weapons research project at Fort Detrick, Maryland. Historian Thomas Boghardt popularized the codename "INFEKTION" based on the claims of former East German Ministry for State Security (Stasi) officer Günter Bohnsack, who claimed that the Stasi codename for the campaign was either "INFEKTION" or perhaps also "VORWÄRTS II". However, historians Christopher Nehring and Douglas Selvage found in the former Stasi and Bulgarian State Security archives materials that prove the actual Stasi codename for the AIDS disinformation campaign was Operation DENVER. The operation involved "an extraordinary amount of effort — funding radio programs, courting journalists, distributing would-be scientific studies", according to journalist Joshua Yaffa, and even became the subject of a report by Dan Rather on the CBS Evening News.

Bulgaria's production strongly depended on auto imports from the Soviet block earlier and currently depends on other European and Asian countries. Presently, Bulgaria introduced its own domestic supercar company, SIN Cars and armed automobiles SAMARM.

References

  1. 1 2 3 4 5 6 7 8 Bennahum, David S. (1 November 1997). "Heart of Darkness". Wired . Retrieved 14 January 2023.
  2. 1 2 Bontchev, Vesselin. "The Bulgarian and Soviet Virus Factories". Section 1 "How the story began". Archived from the original on 10 December 2008. Retrieved 12 October 2009.
  3. 1 2 Bontchev, Vesselin. "The Bulgarian and Soviet Virus Factories". Section 2.1 "The first Bulgarian virus". Archived from the original on 10 December 2008.
  4. 1 2 3 4 Briscoe, David (29 January 1993). "Bulgarian Computer Virus Writer, Scourge in the West, Hero at Home". Associated Press . Retrieved 14 January 2023.
  5. 1 2 Belsie, Laurent (19 May 1992). "Bulgarian 'Dark Avenger' Part of East-Bloc Legacy". Christian Science Monitor . Retrieved 14 January 2023.
  6. 1 2 Mühlbauer, Peter (1 August 2001). "Warum eigentlich Manila?". Heinz Heise (in German). Retrieved 14 January 2023.
  7. DBNL. "Nieuw Letterkundig Magazijn. Jaargang 32 · dbnl". DBNL (in Dutch). Retrieved 2 March 2020.
  8. Mulisch, Harry (2012). Harry Mulisch LOGBOEK 1991–1992. Amsterdam: De Bezige Bij. pp. 114, 115, 122–125. ISBN   978-90-234-2836-7.
  9. 1 2 Bontchev, Vesselin. "The Bulgarian and Soviet Virus Factories". Section 2.3 "The Dark Avenger". Archived from the original on 10 December 2008.
  10. 1 2 Fiscutean, Andrada (5 February 2015). "How Eastern Europe's villains changed sides in the malware war - and made you protect your PC". ZDNet . Retrieved 14 January 2023.
  11. Gibson, Steve (27 April 1992). "Tech Talk". InfoWorld . Vol. 14, no. 17. p. 36.
  12. Campbell, Q.; Kennedy, David M. (2009). "The Psychology of Computer Criminals". Computer Security Handbook. John Wiley & Sons. p. 12.20.
  13. Fasbinder, Joe (14 February 1993). "The Bulgarian virus connection". United Press International . Retrieved 14 January 2023.
  14. Parikka, Jussi (2007). Digital Contagions. Peter Lang. p. 182. ISBN   978-1-4331-0093-2.