AIDS Trojan, also known as Aids Info Disk, Aids Info Drive, and the PC Cyborg Trojan, is a DOS trojan horse from 1989 that is widely regarded as one of the earliest ransomware families. It was distributed on floppy disks labeled the "AIDS Information Introductory Diskette," including mailings to attendees of the World Health Organization’s AIDS conference. The malware replaced AUTOEXEC.BAT to track system boots and, depending on the version, activated after 90 boots or on the first boot after installation. Its payload hid directories and encrypted directory and file names on the C: drive, rendering the system largely unusable; multiple sources in the content also describe it as using a simple symmetric encryptor and blocking access to files, while noting that it did not encrypt file contents themselves. Victims were instructed to "renew the license" by sending US$189 to a Panama post office box associated with PC Cyborg Corporation. The malware is attributed to Dr. Joseph Popp, who distributed the disks and was later charged in connection with the scheme. Recovery was possible because of weaknesses in its symmetric encryption approach, and tools such as AIDSOUT and CLEARAID were described as enabling removal and restoration without paying the ransom. The content does not provide specific technical IOCs such as hashes, domains, or file paths beyond AUTOEXEC.BAT modification and the Panama P.O. box payment demand.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Early ransomware that encrypted files and demanded payment from victims, distributed via floppy disks.
Early ransomware distributed via floppy disk that blocked access to files and demanded payment by mail.
DOS trojan that replaces AUTOEXEC.BAT to track boot count; after a trigger (commonly 90 boots, though variants trigger earlier) it hides directories and encrypts directory/file names on C:, rendering the system unusable and demanding payment to “renew the license” via PC Cyborg Corporation.
Early ransomware trojan (1989) that encrypted filenames and demanded payment to restore access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.