TDTESS is a Windows malware implant that establishes persistence by installing itself as a service when executed with administrative privileges. It has been observed creating a service masquerading as a legitimate component and then manipulating file creation timestamps to match those of a benign system binary, indicating deliberate defense-evasion and anti-forensics tradecraft. During installation, it creates and subsequently deletes log files, further reducing forensic visibility. TDTESS also provides reverse shell functionality on compromised hosts, enabling remote command execution and post-compromise operator access. The documented behavior supports classification as a backdoor-oriented implant focused on persistence, shell access, and stealth on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that copies creation times from legitimate svchost.exe to persistence-related service files.
Backdoor malware that creates and then deletes log files during service installation.
Malware that installs itself as a Windows service named bmwappushservice when running with admin privileges.
Malware/tool that provides a reverse shell on victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.