There is no single, evidence-based answer to which malware attack was “first” or “worst.” The Morris worm is an early internet-scale warning; WannaCry is a clear example of ransomware spreading like a worm; and GameOver Zeus illustrates financially destructive cybercrime. Those are different kinds of harm, so they cannot be placed on one reliable scale. Here are five documented cases and the measure each one helps explain—not a definitive top 15.
Why “first” and “worst” are hard to rank
“First” depends on what counts: the first known malicious program, the first attack of a particular type, or the first incident to affect a large network. “Worst” is similarly ambiguous. An incident might be judged by how quickly it spread, how many systems it reached, financial losses, service disruption, or physical consequences. A large infection count does not automatically mean greater harm than a smaller attack with severe operational effects.
The figures available for the cases below are not a comparable dataset. Some describe affected computers; another combines infections with estimated financial losses. Treat each number as a specific source’s account, not as a score in a universal ranking.
Five cases that show different kinds of impact
Morris worm (1988): an early internet-scale warning
The FBI dates the worm’s release to November 2, 1988, and estimates that it affected about 6,000 of the roughly 60,000 computers then connected to the internet within 24 hours. The FBI says it slowed vital functions and disrupted email but did not destroy files. Robert Tappan Morris was convicted in 1990 under the Computer Fraud and Abuse Act; the FBI describes the case as the first conviction under that 1986 law. The incident also helped prompt the creation of the first computer emergency response team days later.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
These details make the worm historically significant, but they do not establish it as the first malware of any kind or prove that it was the worst attack by every measure.
Stuxnet: malware with specialized technical behavior
Microsoft describes Stuxnet as multi-component malware that could spread through removable drives and exploit a Windows shortcut vulnerability. Those details show how malware can use more than one route to propagate. They do not, on their own, establish who created it or the full extent of its physical effects, so those claims should not be treated as settled on the basis of this technical description.
WannaCry (2017): ransomware with worm-like spread
Microsoft’s 2017 analysis says WannaCry exploited the SMB vulnerability CVE-2017-0145 to spread to unpatched Windows systems. The exploit code Microsoft observed targeted unpatched Windows 7 and Windows Server 2008 or earlier. Microsoft said it had not determined the exact initial entry vector, so an email-only origin should not be presented as established fact.
At the time, Microsoft recommended applying the MS17-010 update. It also described disabling SMBv1 and blocking inbound SMB as workarounds. These are dated recommendations from 2017, not a complete current security plan; organizations should follow current vendor guidance for their systems.
Petya/NotPetya (2017): a software-update route into networks
Microsoft said the initial delivery came through Ukrainian company M.E.Doc’s update service, followed by spread across networks using vulnerabilities or stolen credentials. The case demonstrates why software supply chains and internal network movement matter in incident response: an organization can face risk both from a compromised update route and from malware moving between systems afterward. Microsoft’s dated guidance included patching and network segmentation; those measures should not be mistaken for a complete present-day control set.
GameOver Zeus: a financially measured operation
Microsoft attributed more than one million infected computers worldwide and over $100 million in linked financial losses to the GameOver Zeus operation in 2014. Those figures belong to that operation; they should not be generalized to all Zeus malware or other campaigns. The case is useful for showing why financial loss is a separate yardstick from speed of spread or operational disruption.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to compare malware incidents responsibly
A meaningful comparison first names the measure and then checks how the evidence was produced. Useful questions include:
- Propagation: Did malware spread through network vulnerabilities, removable media, stolen credentials, or a software-update channel? Was it capable of automatic spread?
- Reach: What systems and places were affected, and does the source provide a measured count or an estimate?
- Consequences: Is the documented harm data loss, financial theft, interrupted services, or physical impact? These outcomes are not interchangeable.
- Evidence: Who reported the figure, when, and what exactly did it measure? A vendor’s estimate for one operation is not a universal count for a malware family.
On the evidence summarized here, the Morris worm is the clearest historical milestone, WannaCry and NotPetya illustrate distinct routes to broad network disruption, and GameOver Zeus has a cited financial-loss estimate. Stuxnet’s cited technical details demonstrate multi-route propagation, but the cited description does not establish its attribution or physical consequences. These distinctions are more defensible than naming one incident the definitive “worst.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

