Frodo, also referred to as 4096 or 4K, is a DOS-era file-infecting virus. The provided content identifies it as the first full-stealth file infector and also describes it as a fast infector capable of infecting files when they are merely opened, not only when executed. Historical context in the source places its discovery in October 1989 in Haifa, Israel. The malware targets PC/DOS executable files and is discussed alongside other classic file infectors from the late 1980s and early 1990s. High-confidence aliases explicitly mentioned in the content are 4096 and 4K. No specific threat actor, industry targeting, infection vector beyond file infection/open events, or concrete indicators of compromise are provided in the supplied material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
File-infecting DOS virus known for stealth behavior and also cited as a fast infector; elsewhere noted to modify non-executable files.
A DOS file-infecting virus known for stealth techniques and also cited as a fast infector; it is also mentioned as modifying non-executable files.
First full-stealth file infector; intended to damage the hard disk on or after September 22, though reported samples instead hung the system due to a corrupted damage routine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.