Stalking TDL4: All Access Pass to the Hard Drive

jamescv7

Level 85
Thread author
Verified
Honorary Member
Mar 15, 2011
13,070
Recently my colleagues and I have been analyzing TDL4 — a variant of the well known malware family TDSS. TDSS, as we know, is and advanced malware that evades detection by going back to where we stopped looking long ago: in the boot sector. Back in the 16-bit DOS days, boot viruses spread from disk to disk, wreaking havoc on our computers– until 32-bit Windows came along and made those viruses obsolete. But the boot sector as a malware container is making a comeback, and bootkits such as TDSS are at the forefront.

Malware writers have figured out that the boot sector is a good way to circumvent detection—a lot of antivirus software does not have as rigorous checks as it had in the past, and it is a good way to circumvent Microsoft’s security settings.

Read More
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top