Alureon

Aliases: Olmarik, Pihar, TDL, TDSS, wowlik

Malware type
rootkit
Family
Malware family
Last IoC activity
2026-05-09 17:45:05
Profile updated
2026-07-07 14:44:12

Context

Alureon, also known as Olmarik or TDSS, is a malware family primarily recognized for its rootkit capabilities. It is designed to subvert the operating system by intercepting system calls, allowing it to steal data and compromise infected systems while remaining undetected by traditional security measures.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Alureon_Auto (yara-rule)

Related threat objects

  • TDL4 (infrastructure)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Alureon (report)
  • contagiodump.blogspot.com — List Of Aurora Hydraq Roarur Files (report)
  • twitter.com — 1496878431719473155 (report)
  • contagiodump.blogspot.com — Purple Haze Bootkit (report)
  • youtube.com — Watch (report)
  • johannesbader.ch — The Dga In Alureon Dnschanger (report)
  • archive.f-secure.com — The Case Of Tdl3 (report)
  • Trend Micro — Troj64 Wowlik.Vt (report)
  • Kaspersky — 36314 (report)
  • virusbulletin.com — Paper Notes Click Fraud American Story (report)
  • contagiodump.blogspot.com — Tdss Tdl 4 Alureon 32 Bit And 64 Bit (report)

External references