BITDEFENDER PARTNER MALAYSIA
  • Home
    • About Us
    • Why Bitdefender >
      • Patented Technology
  • FOR BUSINESS
    • Gravityzone Business Security >
      • Ransomware Mitigation
      • MITRE ATT&CK Evaluation
      • Gravityzone Technologies
      • Gravityzone Features List
    • Bitdefender Email Security >
      • Gravityzone Email Security Configuration (For Outlook 365)
      • Gravityzone Email Security Configuration (For Google Workspace)
    • Patch Management
    • Full Disk Encryption
  • SUPPORT
    • Payment mode
    • Request Quotation
    • Tips & Trends
    • Refund Policy
    • Privacy Policy
  • CONTACT US
    • Whatsapp us

22 years of Innovations

The ABC of Cybersecurity: R is for Rootkit

10/6/2016

 
Picture
Rootkits are some of the most sophisticated breeds of malware that currently exist on the market. For years, security solutions have struggled with detection and removal, mostly because rootkits compromise the operating system at such a low level, that they can hide their presence from both anti-malware solutions and the operating system itself.
​

The term rootkit is a concatenation of the words “root” – the most privileged user on a Unix-based operating system and “kit” – the set of software tools that make the rootkit. Rootkits go back to the early 90s when they were focused on Sun and Linux, but the emergence of new operating systems led to the development of rootkits for Windows in 1999 and Mac in 2009.
What are rootkits and how do they work?

Unlike traditional malware, rootkits introduce a fundamental flaw in the computer they infect. They do not compromise files or folders – instead, they alter everything that the operating system reports back to you according to their creator’s needs.

Rootkits are broken down into two main categories: user-mode or kernel-mode rootkits, depending on their scope of action. In order to get a glimpse of how they compromise an operating system, we need to first understand how an operating system works. All applications on your computer communicate via function calls passed through the operating system’s API (application Programming Interface). A user-mode driver hooks the Import Address Table (a list of all addresses of APIs or system functions that the program needs the operating system’s kernel to perform).

Kernel-mode rootkits use system drivers that attach to the kernel to “intermediate” API calls between user applications and the operating system itself. Once it is installed, the rootkit driver redirects system function calls so its own code is executed instead of kernel code. So when you’re opening a folder to see its contents, you are ususerually interrogating the kernel about the number of files residing in the respective folder. However, a rootkit could intercept your request and report all the files in the folder, except for some that are malicious. You, your operating system or your anti-malware product won’t even know that some files ever existed in the respective folder.

By using a rootkit, a criminal has full administrator privileges to your computer and software, conveniently accessing logs, monitoring your activity, stealing private information and files, and messing with configurations. Without you even knowing, all your passwords and information will be available for them to steal.

Even if they are some of the most dangerous e-threats to date, rootkits don’t just work by themselves – they need an infection vector to propagate and install. Hackers use Trojans or leverage operating system vulnerabilities to plant rootkits. But once they have made it to the system,  they are often harboring spyware, worms, key loggers or computer viruses which turn your computer into a worthless zombie. Hackers can subsequently use it to launch DoS attacks, spam and phishing campaigns on third parties, maybe even on your contacts. Having root access to the operating system, your computer is completely taken over by hackers, making rootkits difficult to immediately detect even for the most experienced tech eye.

But rootkits are not always malware, as in some cases they are used for cheating purposes such as defeating copyright and anti-theft protection. On the other hand, Sony and Lenovo are companies known to have inserted rootkits in users’ devices to reinstall unwanted software or as part of digital rights management. Although implanted with harmless intent, these are vulnerabilities which make it easy for hackers to later exploit if uncovered.

Rootkit red flags and how to remove it

Detecting them is strenuous and might prove impossible due to their complete control over your computer, including over any software you might choose to remove it. If you are a tech-savvy victim, there are some steps you could follow such as signature scanning or memory dump analysis, but if the rootkit has taken over the kernel memory (aka the brain of your operating system), then accept defeat; format the hard disk and reinstall your operating system.

As you’ve probably figured out by now, rootkits are so sophisticated that you might not be able to get rid of them without a re-installation. In fact, you may probably not even detect them until it’s too late or you try to run a scan and it doesn’t allow your antivirus to start. To avoid losing all your data, make sure you develop some appropriate online browsing habits.

Encrypt your private information and make sure to save it in multiple sources, just to be safe. Because the most common way for a hacker to get into your network are Trojans, never open email attachments from senders you’ve never heard of. If you’re casually streaming a video or want to open a file and are asked to download a plugin, don’t. Constantly update your firewall and security solution and periodically run full system scans on your computer.

Source: Hot for Security powered by Bitdefender
Get your personal protection now
Get your business protection now

Comments are closed.

    Protect from Ransomware

    Buy Bitdefender now

    Select carefully in the PayPal item below before make payment.
    Buy now and get protection. License key will be delivered before next business day. Activation in Malaysia only.

    Picture

    RECOMMENDED READINGs

    All
    ABC Of Cybersecurity
    Antivirus For Mac
    Biometric
    Child Online Safety
    CISO
    Corporate Security
    Cyberattacks
    Cybersecurity
    Data Center
    Data Center Security
    Data Leak
    Do Your Thing
    Endpoint Security
    Extortion
    Firewall Rules
    Goldeneye
    Gravityzone Business Security)
    Hacker
    Home Security
    Home User Products
    How To
    Hyperconvergence
    Installation Guide
    Intellectual Property
    Internet Of Things
    Internet Security
    IoT
    Loss Of Life
    Machine Learning
    Malware
    Online Purchase
    Online Security
    Parental Control
    Personal Security
    Petya
    Protected
    Ransomware
    Ransomware 2016
    Ransomware Decryption Tool
    Security Awareness
    Security Awareness Training
    Security Policies Setting
    Smb
    Virtualization & Cloud Security
    Wannacry
    Wanncry
    Windows Security

    RSS Feed

Picture
Chat with WhatsApp
Picture
Submit request or inquiry

For BUSINESS: Gravityzone Advanced Business Security

We are a certified Bitdefender Solution Partner (more than 9 years)

Copyright © 2025 We are a Gold Partner of Bitdefender.
About us | Contact us |
Copyright © 2024 57Network Consultancy Sdn. Bhd.
Company Registration number: 202001020346 (1376666-K) 
All rights reserved.

Website managed by 57Network.com
  • Home
    • About Us
    • Why Bitdefender >
      • Patented Technology
  • FOR BUSINESS
    • Gravityzone Business Security >
      • Ransomware Mitigation
      • MITRE ATT&CK Evaluation
      • Gravityzone Technologies
      • Gravityzone Features List
    • Bitdefender Email Security >
      • Gravityzone Email Security Configuration (For Outlook 365)
      • Gravityzone Email Security Configuration (For Google Workspace)
    • Patch Management
    • Full Disk Encryption
  • SUPPORT
    • Payment mode
    • Request Quotation
    • Tips & Trends
    • Refund Policy
    • Privacy Policy
  • CONTACT US
    • Whatsapp us