7 Things to Know about Virus Writers
What Do Virus Writers Actually Want — and How Can Businesses Stay Protected?
Cybersecurity threats don't emerge from a vacuum. Behind every virus, every malicious payload, and every self-replicating piece of code is a human being with a motive — or sometimes, surprisingly, no clear motive at all. Understanding the psychology and behavior of virus writers is one of the most underrated elements of building an effective security posture. I spend a growing percentage of my time getting rid of unwanted emails that contain viruses. If I open one of them, it potentially could overwrite files and disable my antivirus software. What exactly is in the heads of these virus writers? Anything?
To answer that question, cybersecurity researcher Sarah Gordon — senior research fellow at Symantec's security response unit and former researcher at IBM's Thomas J. Watson Research Center — offers a grounded, research-backed profile of who these individuals are and what drives them. For organizations looking to move beyond reactive defenses, firms like eMazzanti Technologies work with small and mid-sized businesses across New Jersey and nationwide to design cybersecurity strategies that account not just for the technology, but for the human behavior behind the threats — helping teams reduce risk before an attack takes hold.
Who Are Virus Writers and What Motivates Them?
Gordon will tell you right away that hackers — people who devise ways to break into networks — are a different animal than virus writers, and in most cases, more advanced. Virus writers are generally younger (some as young as 10 or 11 years old), on a lower rung of the underground tech strata, and not always aware of the damage they can cause. Also worth noting: except in a few states, writing damaging viruses isn't against the law, which means the barrier to entry is remarkably low.
Courtesy of Gordon, here are seven things about virus writers that every business leader and IT professional should understand.
1. They're often kids, but not always.
In general, virus writers are young people under 30 and predominantly male. Many are in their teens. But stereotypes can be dangerous here, because some veteran IT professionals have been known to write viruses on the side to "test the security" of certain networks and systems. "Often people 'play around' with viruses, not realizing the damage they can cause. They think that because they can't 'see' them do anything, it's all OK." Generally, the older a virus writer is, the more that he knows what he is doing — though this varies from country to country.
2. Their goals vary, and many don't even have goals.
Some are simply exploring self-replicating code as a programming exercise. Others are trying to gain notoriety or make a personal, political, or social statement. A few are disgruntled workers. "Generally, many young people who write viruses don't connect the act with the damage that can occur... That said, some virus writers have a pretty good idea of the end result, and do it anyway. These tend to be older individuals, who write viruses with the intent of causing damage and chaos."
3. Their targets are generally random.
Many virus writers claim to be exposing the vulnerabilities of a software product or a specific company. Gordon contends that many use that as an excuse for an adventure gone further than anticipated. "Most viruses don't appear to be written with destruction in mind. Many are written to be destructive — and while there may be a political or social statement in them, they are generally pretty much randomly targeted."
4. Virus writers aren't necessarily rocket scientists.
This isn't a comment on their intelligence, but rather a warning: it doesn't take elite technical skills to write damaging viruses. "Virus writing is not rocket science, and it doesn't take any special elite skill to be able to write a self-replicating program." Those who create the most destructive payloads — the Klez, SirCam, and Nimda viruses, for example — may be technically sophisticated, but most virus writers are not. As their skills advance, they often move on to other pursuits entirely. "As virus writers 'age out,' new virus writers take their places."
5. Virus writers feed off new technology and each other's innovations.
Serious virus writers don't reinvent the wheel — they build on what has caused havoc in the past and take advantage of the latest tools and technologies. As a result, tomorrow's viruses are likely to be more complicated and potentially much more destructive than today's.
How Does Education Factor into Stopping Virus Writers?
Gordon believes that families and schools, in the Internet Age, have an obligation to teach children how to behave on the computer — to extend moral and ethical behavior from the real world to the virtual world. Children need to understand that reading another person's email is just as wrong as opening a letter from a neighbor's mailbox. She also chastises journalists for frequently overestimating the damage virus writers do, thereby glorifying their acts. "While the media are starting to realize that virus writers are not geniuses, or heroes 'helping' us to understand security risks, there is still a long way to go — especially in countries where viruses are relatively new and where ethics is not part of the curriculum."
"This technology lends itself well to depersonalization and de-sensitization. We need to learn more about the dynamics of computer-mediated communication, and find ways to help real-world values transfer to virtual interactions."
What Security Measures Should Businesses Put in Place Today?
Before education has measurable impact, the technical defenses need to be fortified — because virus writers are already building on each other's work. Gordon recommends that businesses maintain both firewall-intrusion protection and antivirus software, and that these solutions be integrated to deal with blended threats. "It is not enough to be protected from just viruses." She also flags the growing risk to mobile devices: while viruses have historically targeted PCs, they are increasingly likely to threaten smartphones and tablets in the years ahead.
For businesses in New Jersey and across the region, the practical takeaway is that a single-layer defense is no longer sufficient. A layered security approach — combining endpoint protection, network monitoring, employee training, and incident response planning — provides the depth needed to keep pace with an evolving threat landscape. If your organization is ready to strengthen its defenses, eMazzanti Technologies can help assess your current security posture and implement a cybersecurity strategy targeted to your specific business needs and budget.
FAQ: Understanding Virus Writers and Business Cybersecurity
Q: Why do people write computer viruses?
A: Motivations vary widely. Some virus writers are young people experimenting with self-replicating code without fully understanding the consequences. Others seek notoriety, want to make a social or political statement, or are motivated by frustration with an employer. A smaller subset deliberately intends to cause damage. Research shows that many — especially younger writers — simply don't connect the act of writing a virus with the real-world harm it causes.
Q: How technically skilled do you have to be to write a computer virus?
A: Less skilled than most people assume. Writing a self-replicating program does not require elite technical knowledge, which is what makes the threat so persistent. While the most destructive viruses — such as Klez, Nimda, and SirCam — were created by more experienced individuals, the majority of virus writers have modest programming skills. The low barrier to entry means new writers continuously replace those who move on.
Q: Are virus writers the same as hackers?
A: No. While both operate in the underground tech space, they are distinct groups. Hackers are generally focused on breaking into networks and tend to be more technically advanced. Virus writers, by contrast, create self-replicating code — often with less precision and, in many cases, less awareness of the damage they cause. Hackers typically have more defined targets, while virus writers tend to release threats into the wild with random reach.
Q: What is the best way for a business to protect itself from viruses?
A: A layered approach is essential. Businesses should deploy both antivirus software and firewall-intrusion protection, and critically, these tools should be integrated to address blended threats that combine viruses with hacking techniques. Employee training is also a key layer — educating staff on which attachments to avoid and how to recognize phishing attempts reduces the likelihood of an infection ever taking hold.
Q: Will computer viruses become more dangerous in the future?
A: Based on current trends, yes. Virus writers build on each other's work and adopt new technologies quickly, meaning future threats are likely to be more sophisticated than today's. The expansion of mobile devices also broadens the attack surface significantly. Organizations that rely on static, single-layer defenses today may find themselves increasingly exposed as threat complexity grows.




