FIELD NOTE / 2026.09.213 MIN READ / 8 SOURCES

The Minds Behind Malware and Antivirus – 7 People Redefining Software

Seven researchers and entrepreneurs helped define computer viruses, commercialize antivirus, and professionalize malware analysis and detection.

TL;DR

Malware research became a discipline when self-replicating code was studied formally and defenders built tools, taxonomies, scanning engines, and response organizations around it. Cohen formalized the virus problem; McAfee commercialized consumer antivirus; Kaspersky, Hyppönen, Gordon, Szőr, and Bontchev advanced analysis, detection, classification, and public understanding.[1][3][4]

Why you should read it anyway

Malware is adaptive software written by adversaries. That makes defense fundamentally different from ordinary debugging: once defenders recognize a technique, attackers deliberately modify code to evade the recognition. Antivirus history is therefore a continuous arms race among signatures, heuristics, emulation, behavior analysis, and reverse engineering.

Imagine where Malware and Antivirus would be without them

Without organized malware research, personal-computer and Internet adoption would have faced far higher infection costs. Worms and viruses would spread longer before detection, and organizations would have fewer shared methods for analysis, naming, removal, and response.

Time Estimate of how many years we would be hindered without them for human progress

Editorial counterfactual estimate: 4–8 years. Malware itself created immediate demand for defensive tools, but formal research and commercial laboratories accelerated the transition from ad hoc cleanup to continuously updated security products.

The 7 people behind Malware and Antivirus

1. Fred Cohen

Why they matter: Cohen carried out controlled experiments on self-replicating malicious programs in 1983 and formalized the computer-virus concept in his research.[1][2] He helped move malware from anecdote into scientific study by asking what viruses can do, how quickly they can spread, and what kinds of defenses are theoretically possible.

2. John McAfee

Why they matter: McAfee became one of the first high-profile commercial antivirus entrepreneurs, building a company around detecting and removing PC viruses. His importance in this article is commercialization and distribution rather than theoretical invention: antivirus became a consumer software category because detection tools were packaged, updated, and sold broadly.

3. Eugene Kaspersky

Why they matter: Kaspersky entered antivirus research after encountering the Cascade virus in 1989 and writing a removal tool.[3] He went on to build malware-analysis and detection technology into a global security company. His contribution represents the transition from manually removing individual viruses to maintaining large continuously updated detection systems.

4. Mikko Hyppönen

Why they matter: Hyppönen became one of the most visible malware analysts of the Internet era, investigating global worms, viruses, and later state-linked threats. His work helped connect technical reverse engineering with public communication about how malware campaigns spread and who they affect.[7]

5. Sarah Gordon

Why they matter: Gordon became a major researcher and writer on malware behavior, virus writers, hoaxes, ethics, and human factors. Virus Bulletin’s long-running archive includes her work across technical and social dimensions of malicious software.[5] Her contribution broadened the field beyond signatures into understanding attacker communities and user behavior.

6. Peter Szor

Why they matter: Szőr was one of the anti-malware field’s leading technical researchers and authored extensive work on virus analysis and detection. Virus Bulletin’s memorial notes that he built foundations of scanning engines and published nearly forty articles with the organization.[4]

7. Vesselin Bontchev

Why they matter: Bontchev became an influential virus researcher focused on classification, detection, and rigorous terminology. Virus Bulletin archives document his long-standing technical participation in the anti-malware community.[6] His work helped professionalize malware taxonomy and analysis as the number and diversity of malicious programs exploded.

How they each differ from one another

Cohen supplied theory; McAfee helped create the mass-market antivirus business; Kaspersky built a large detection-and-analysis operation; Hyppönen became a leading outbreak investigator; Gordon researched human and ethical dimensions; Szőr advanced scanning-engine and malware-analysis techniques; Bontchev strengthened classification and technical rigor.

Final Take

Antivirus was never a static cure. It became an intelligence system: collect samples, reverse engineer them, extract behavior, distribute detections, monitor new variants, and repeat. Modern endpoint security adds telemetry and behavior models, but it still inherits that operational loop.[8]

RESEARCH / PROVENANCE

Works Cited

8 SOURCES
  1. 01
  2. 02
  3. 03
  4. 04
  5. 05
  6. 06
  7. 07
  8. 08

CodeHistory is a living archive. Citations document the evidence used for this edition; later evidence may refine the account.

Contribute / Corrections

Improve the record.

Use this moderated submission form to suggest a correction, provide a source, challenge a priority claim or identify a missing contributor. Submissions are treated as research leads, not automatically published comments.

Submit a research lead

Please do not submit confidential material or claims you cannot support.