← MALWARE HISTORY LAB

HISTORICAL ARCHIVE · CHAPTER 01 / 09

Early Experiments

1970S · RESEARCH NETWORKS

A safe, curator-led account of a technical transition in malware history. All illustrations are conceptual and inert.

ERA / DATE RANGE1970s · Research networks
REPRESENTATIVE EXAMPLESCreeper · Reaper
ARCHIVE STATUSHISTORICAL CONTENT: OPEN

What changed?

Self-replication began as a theoretical and experimental idea on early networked computers. Creeper is historically important as an early moving, self-replicating program, but it should not automatically be equated with the later malicious malware category.

How it spread / worked conceptually

An experimental program could move between connected systems in a small research environment. Reaper is remembered as an early defensive response concept: find the program, remove it, and return the system to a clean state.

Why it mattered

It established a lasting question for computing: when software can copy or move itself, who controls that behavior and how is it observed?

SAFE CONCEPTUAL DIAGRAM NO LIVE ACTIVITY
EXPERIMENTAL NETWORKNODE A → NODE B → NODE CCREEPER DETECTED ↓ REAPER SEARCH ↓ REMOVE / CLEAN

Representative historical examples

Creeper (early 1970s) is often cited in histories of networked self-replication. Reaper followed as a program intended to locate and remove Creeper.

What defenders learned

The response model was already recognizable: observe unexpected behavior, locate it, and clean it.

What changed next?

Self-replication would soon leave research networks and encounter a new distribution medium: removable disks.