A rootkit hides its presence and maintains privileged access. The name comes from root, the highest privilege level on Unix systems, and kit, a set of tools. A rootkit buries itself deep in the operating system. It may modify kernel structures, intercept system calls, or replace legitimate binaries with trojanized versions. The goal is to be invisible. Antivirus software that relies on seeing files and processes cannot see what the rootkit hides.
Rootkits come in different forms. User-mode rootkits hook APIs to hide their processes and files. Kernel-mode rootkits patch the kernel itself, which gives them the highest level of control. Bootkits infect the bootloader or firmware, so they load before the operating system and survive reinstallation. Hardware rootkits live in firmware or device controllers, which makes them extremely difficult to detect and remove. The Sony BMG rootkit scandal in 2005 showed how a legitimate company could deploy rootkit-like software. Sony's copy protection hid itself from users and created security holes. The backlash was severe. Detecting rootkits requires specialized tools that compare system state against known-good baselines. Removal often means wiping the system and reinstalling from scratch. You cannot trust a machine that a rootkit has touched.
Rootkit types
- User-mode — hooks APIs to hide processes and files
- Kernel-mode — patches the kernel for deep control
- Bootkit — infects the bootloader, loads before the OS
- Firmware — lives in hardware, survives reinstallation
Rootkits are about persistence and stealth. They are not the initial attack. They are what remains after the attacker has settled in.
Comments
No comments yet. Be the first to share a thought.
Leave a comment