ESET Threat Blog
David Harley

TDSS: The Next Generation

by David Harley Senior Research Fellow
March 30, 2011 at 11:37 am

Win32/Olmarik (also known as TDSS, TDL, Alureon and sundry less complimentary names) has gone through some interesting evolutions in the last couple of years.

TDL4 is no exception, with its ability to load its kernel-mode driver on systems with an enforced kernel-mode code signing policy (64-bit versions of Microsoft Windows Vista and 7) and perform kernel-mode hooks with kernel-mode patch protection policy enabled.

In a new ESET white paper on The Evolution of TDL: Conquering x64,  Eugene Rodionov and Aleksandr Matrosov look at the GangstaBucks gang that has been distributing TDSS since DogmaMillions shut up shop, then dive deeper into analysis of the bootkit.

You may also find their previous white paper TDL3: The Rootkit of All Evil? and Virus Bulletin article Rooting about in TDSS* of interest.

* Available on the white papers page by courtesy of Virus Bulletin, who hold the copyright.

David Harley CITP FBCS CISSP
ESET Senior Research Fellow   

.

4 Responses to “TDSS: The Next Generation”

  1. Henri Salo Says:

    Your links are broken.

  2. David Harley Says:

    ?!*?£$! Again!!!! Thanks, Henri. Fixed, I hope.

  3. Randy Knobloch Says:

    Great write up, David – thank you.
    Are the in working order – are they current ?
    Regards,

  4. David Harley Says:

    Randy, do you mean the links? They were mysteriously corrupted when the post was posted. That happens on this blog occasionally: I must remember to check them after they're posted as well as before, but it hasn't happened for a while and I got sloppy. :)

Leave a Reply

Share |
Subscribe by Email
To receive new posts automatically through email, enter your email address:

Delivered by FeedBurner

Blog Search
Archives

Switch to our mobile site