Alureon is a Windows malware family best known as a rootkit and downloader platform that has also been used in click-fraud and traffic-manipulation operations. It has been associated with multiple malicious components that alter core system behavior, including changing DNS settings, disabling or clearing proxy settings, copying itself under random names, injecting threads into local processes, and establishing stealthy persistence. Some variants tamper with storage miniport drivers, including common ATA and RAID-related drivers, which can render targeted drivers unusable and increase system instability while helping the malware gain control early in the boot or storage stack. Alureon has also been documented as part of broader monetization ecosystems involving ad-click fraud, and clickbot modules attributed to Alureon have been assessed as highly similar to the Pigeon module used by the Blackbeard/Pigeon malware family, suggesting shared development lineage or code reuse.
On infected systems, Alureon can modify network configuration so attacker-controlled DNS servers are used for adapters and dial-up connections, then force the changes to take effect immediately. It also employs process injection and creates persistence-related registry artifacts. Its rootkit behavior and driver tampering make it notable for defense evasion and long-term footholds on compromised hosts. Alureon primarily targets Microsoft Windows systems and has historically been treated as a significant example of Windows rootkit malware used for post-compromise monetization and traffic redirection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Later on, it modifies several keys in the Windows registry... Pigeon sets ‘HKCU\Software\Microsoft\Internet Explorer\Main\NoNewWindows’ to 1.
The boot option is changed in memory from the code executed by infected MBR... The rootkit changes this config setting value to a low level of validation that effectively allows loading of an unsigned malicious rootkit dl file.
Improved disk minport filtering hook ... First kernel mode rootkit compatible with x64 Windows.
A second Alureon component does the following: Create a randomly named copy of itself in the <system folder>
The reply to the second POST request is encrypted with RC4. It contains the main module, which is then decrypted, injected into the svchost.exe process, and executed.
To let these new DNS settings immediate effect, Alureon runs the following commands: ipconfig.exe /flushdns ipconfig.exe /registerdns ipconfig.exe /dnsflush ipconfig.exe /renew ipconfig.exe /renew_all
The boot option is changed in memory from the code executed by infected MBR... The rootkit changes this config setting value to a low level of validation that effectively allows loading of an unsigned malicious rootkit dl file.
First kernel mode rootkit compatible with x64 Windows. Uses bootkit technique to load itself and bypass drivers signing restriction on x64
It creates a hidden VFS to store all the data. The list of hidden system files: Phdata [PurpleHaze]
0.03 September 2010, small changes, new C&C library ... Uses payload C&C dll injection
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
See also Alureon, Botnet, Conficker, Gameover ZeuS, Regin (malware), Technical support scam...
Alureon is described as a related clickbot/rootkit module similar to Pigeon. It runs inside svchost.exe -netsvcs, modifies registry keys, processes task URLs in the same format as Pigeon, and performs hidden-browser click fraud.
Mentioned only in sidebar link titles; one occurrence appears misspelled as 'Alueron'.
2007 Alureon BlackEnergy Clampi Mebroot Storm ZeuS
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.