Netskope Threat Labs

TDss

ATP Sandbox Adv. HeuristicsAV

TDss (a.k.a. TDL) is a family of sophisticated rootkits that infected the master boot record of Windows machines to hide their botnet components below the operating system. Its operators rented capacity to other crews and harvested banking credentials, and later variants such as TDL4 resisted cleanup with encryption and plugin architectures.

First seen
January 2022
Last seen
October 2026
Tdss
Alert Name
Boot.Rootkit.TDss
Gen:Variant.TDss.18
Gen:Variant.TDss.20
Gen:Variant.TDss.21
Gen:Variant.TDss.23
Gen:Variant.TDss.24
Gen:Variant.Tdss.27
Gen:Variant.TDss.33
Gen:Variant.TDss.38
Gen:Variant.TDss.40