Information World's stealthiest rootkit gets a makeover

Discussion in 'Tech Security News' started by Kedar, Oct 22, 2011.


  1. Kedar Geek

    PCHF Staff
    Message Count:
    9,240
    Likes Received:
    786
    My System
    Loading...
    One of the world's more advanced pieces of malware has just gotten a makeover that could make it even more resistant to takedown efforts, security researchers said.

    An analysis of recent updates to the TDL4 rootkit, which is also known as TDSS and Alureon, shows that components including its kernel-mode driver and user-mode payload have been rewritten from scratch, researchers from antivirus provider ESET blogged earlier this week.

    The code overhaul may mean that operators of TDL4, which is used to force keyloggers, adware, and other malicious programs onto compromised machines, may have started providing services to other crimeware groups.
    The makeover includes changes to the way TDL4 attempts to remain undetected by antivirus programs and other defenses.

    Newer versions create a hidden partition at the end of the infected machine's hard disk and set it to active. This ensures that malicious code stashed in it is executed before the Windows operating system is run....


    World's stealthiest rootkit gets a makeover ? The Register

  2. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,774
    Likes Received:
    883
    My System
    Loading...
    Open for discussion.

World's stealthiest rootkit gets a makeover