Rootkits: evolution and detection methods
A rootkit is a program (or set of programs) that allows you to hide the presence of malware in the system. Rootkits are often part of multifunctional malware that could have multiple abilities, such as providing attackers with remote access to compromised hosts, intercepting network traffic, spying on users, recording keystrokes, stealing authentication information, or using the host as a base to mine cryptocurrencies and aid in DDoS attacks. The task of the rootkit is to mask this illegitimate activity on the compromised machine. Some rootkits, such as Necurs, Flame and DirtyMoe, are designed to combine both modes of operation and thus work at both levels. They accounted for 31% of the sample.
Nov-8-2021, 00:05:31 GMT
- Country:
- Africa > Middle East (0.05)
- South America > Brazil (0.04)
- North America > United States (0.04)
- Europe
- Middle East (0.05)
- United Kingdom (0.04)
- Romania (0.04)
- Italy (0.04)
- France (0.04)
- Asia
- India (0.05)
- Southeast Asia (0.04)
- Indonesia (0.04)
- China (0.04)
- Middle East
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: