Tequila is a DOS-era multipartite computer virus discovered in 1991. It infects both executable files and disk boot sectors, allowing propagation through infected software and bootable removable media. Tequila combines several advanced evasion features for its period, including stealth techniques, polymorphic code, tunneling, and anti-antivirus behavior intended to hinder detection and analysis. It also includes a visible payload that can display a Mandelbrot fractal. Tequila affected IBM PC-compatible systems running DOS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multipartite virus cited as a later example of malware using multiple infection vectors.
A virus noted here for displaying a Mandelbrot fractal as part of its payload.
Multipartite virus capable of infecting both files and boot sectors.
A multipartite virus capable of infecting both files and boot sectors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.