TDL4, also known as Olmarik, is a Windows MBR bootkit and rootkit family active from approximately 2010. It overwrites Master Boot Record code to execute before Windows, initializes malicious components during boot, and loads unsigned kernel-mode drivers from concealed disk storage, enabling persistence and evasion of 64-bit kernel driver-signing controls. TDL4 includes user-mode functionality that manipulates browser network traffic by hooking Windows socket-provider functions; related components have been associated with click-fraud behavior. It uses RC4-encrypted command-and-control communications and has been observed receiving commands to download and execute additional malware. TDL4 is associated with the broader TDSS/Olmarik family and shares traffic-manipulation techniques with Win32/Agent.TJO and Win32/Redyms. It targets legacy BIOS/MBR-based Windows systems rather than UEFI boot flows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
It lowers internet security settings to enable the clicker component perform extensive browsing without any alerts or pop-ups.
Improved disk minport filtering hook ... First kernel mode rootkit compatible with x64 Windows.
Uses payload C&C dll injection (cmd.dll for x86 and cmd64.dll for x64).
The boot option is changed in memory from the code executed by infected MBR... The rootkit changes this config setting value to a low level of validation that effectively allows loading of an unsigned malicious rootkit dl file.
It creates a hidden VFS to store all the data. The list of hidden system files: Phdata [PurpleHaze]
0.03 September 2010, small changes, new C&C library ... Uses payload C&C dll injection
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a historical example of earlier bootkits during the peak bootkit era.
Referenced as a related malware family sharing similar browser traffic manipulation, hooking techniques, and RC4-encrypted communication patterns with Win32/Redyms.
TDL4 is described as malware that installs, contacts a C&C server, and receives commands to download and execute additional binaries such as Glupteba.
An MBR-based bootkit that initializes malicious components at boot time and loads a malicious kernel-mode driver from hidden storage, bypassing Microsoft's kernel-mode code signing policy on x64 systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.