Kaspersky reported that TDL-4, an advanced evolution of the TDSS malware family, combined bootkit persistence, a powerful rootkit, and custom-encrypted HTTPS communications to create one of the most resilient malware platforms of its time. The malware hid itself and other payloads, removed competing malware from infected systems, and blocked rival botnet infrastructure, while also supporting monetization through proxy services, search-result manipulation, and advertising fraud. Kaspersky’s analysis of backend databases indicated that 4,524,488 computers were infected in the first three months of 2011, with nearly one-third of victims located in the United States.
A key innovation was TDL-4’s use of the public Kad peer-to-peer network through the kad.dll module, allowing operators to distribute commands and maintain control even if traditional command-and-control servers were taken down. Additional components such as Socks.dll enabled proxy functionality and cmd64.dll added 64-bit support, extending the botnet’s reach and durability. Researchers said the architecture was designed to make the botnet effectively indestructible, underscoring how TDL-4 raised the bar for stealth, survivability, and criminal monetization in large-scale malware operations.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
By May 2011, analysis showed TDL-4 had evolved into a highly sophisticated TDSS variant using bootkit functionality, rootkit stealth, encrypted HTTPS communications, and the public Kad P2P network via kad.dll for command and control. The malware also monetized infections through proxy services, search-result manipulation, ad fraud, and included 64-bit support while removing competing malware.
Kaspersky Lab's analysis of backend databases found that TDL-4 infected 4,524,488 computers during the first three months of 2011, with nearly one-third of infections located in the United States. This established the scale of the botnet's global spread.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 75 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.