TDSS, also known as the TDL family and including the TDL-4/Alureon lineage, is a Windows kernel-mode rootkit and bootkit platform first observed in 2008. Early variants concealed registry data, files, processes, network ports, injected modules, and malicious drivers through kernel hooking and driver infection. Later versions achieved early-boot persistence by infecting disk drivers or the master boot record, storing encrypted components in protected disk sectors, and loading before Windows. TDL-4 added 64-bit support, encrypted command-and-control communications, peer-to-peer command distribution using the Kad network, and functionality to remove competing malware and obstruct connections to rival botnet infrastructure. TDSS operators used infected systems for additional malware delivery, search-result and advertising-traffic manipulation, click fraud, and proxy services that monetized compromised hosts. Distribution occurred through affiliate and pay-per-install programs, including drive-by compromise of websites, fake codec lures, key generators, and installation by other malware. The family was associated with Russian-speaking cybercriminal operations and was among the most technically sophisticated Windows rootkit platforms of its era.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Intel 471 labeled Yalishanda as one the 'top tier' bulletproof hosting providers worldwide, noting that in just one 90-day period in 2017 his infrastructure was seen hosting sites tied to some of the most advanced malware contagions at the time, including the Dridex and Zeus banking trojans, as well as a slew of ransomware operations.
It lowers internet security settings to enable the clicker component perform extensive browsing without any alerts or pop-ups.
Just like Sinowal, TDL-4 is a bootkit, which means that it infects the MBR in order to launch itself, thus ensuring that malicious code will run prior to operating system start.
First kernel mode rootkit compatible with x64 Windows. Uses bootkit technique to load itself and bypass drivers signing restriction on x64
Improved disk minport filtering hook ... First kernel mode rootkit compatible with x64 Windows.
Uses payload C&C dll injection (cmd.dll for x86 and cmd64.dll for x64).
To prevent other malicious programs not associated with TDL from attracting the attention of users of the infected machine, TDL-4 can now delete them.
Just like Sinowal, TDL-4 is a bootkit, which means that it infects the MBR in order to launch itself, thus ensuring that malicious code will run prior to operating system start.
First kernel mode rootkit compatible with x64 Windows. Uses bootkit technique to load itself and bypass drivers signing restriction on x64
0.03 September 2010, small changes, new C&C library ... Uses payload C&C dll injection
AWM Proxy — a 14-year-old anonymity service that rents hacked PCs to cybercriminals
A file called Socks.dll has been added to TDSS’s svchost.exe; it is used to establish a proxy server on an infected computer.
Fizot... helped customers anonymize their cybercrime traffic by routing it through a global network of Microsoft Windows computers infected with a powerful malware strain called TDSS.
TDSS uses a public P2P network in order to transmit commands to all infected computers in the botnet.
By default, tldcmd.dll can execute the following commands sent from the C&C: DownloadCrypted: download an encrypted file. DownloadAndExecute: download and execute a file. DownloadCryptedAndExecute: download an encrypted file, decrypt and run it. Download: Download a file.
101 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealthy rootkit that installs deeply on infected PCs before Windows boots and was used to compromise systems and deploy Glupteba.
A sophisticated rootkit/bootkit botnet malware family that infects the MBR for persistence, encrypts communications with command-and-control servers, hides itself and other malware, removes competing malware, manipulates search results and advertising traffic, supports proxy services via infected hosts, uses Kad P2P for resilient command distribution, and downloads additional payloads such as adware, fake antivirus, and spam bots.
Listed as one of multiple payloads downloaded by Bredolab onto victim systems.
A sophisticated rootkit family that evolved through multiple versions to infect drivers and disk components, hide files/registry keys/network activity, maintain persistence early in the boot process, communicate with C2 over HTTPS with encrypted requests, and load payloads such as click-fraud, search result spoofing, and additional malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.