Glossary
Rootkit
Malware designed to gain and conceal privileged access to a system, often by modifying the operating system's core components to hide its own processes, files, and network connections from standard monitoring tools. Because rootkits can subvert the OS itself, they are among the hardest malware types to detect and remove.
Recent coverage mentioning Rootkit
UAT-10147 Leverages Agentic AI for EDR-Evasive Cybercrime
Talos details UAT-10147, an AI-driven cybercrime group orchestrating sophisticated post-compromise operations and evading EDR with custom rootkits.
SPECTRE Malware: UAT-10147 Targets IIS, Linux Servers with Rootkits
Chinese-speaking actor UAT-10147 deploys SPECTRE, a cross-platform implant featuring Linux rootkit and BYOVD EDR bypass capabilities.
SonicWall SMA1000 Exploited: Ransomware Targets CVE-2026-15409/15410
CISA confirms ransomware exploitation of SonicWall SMA1000 flaws CVE-2026-15409 and CVE-2026-15410, urging immediate patching.
UEFI Shim Bootloader Vulnerabilities: Secure Boot Blind Spot
Nearly a dozen vulnerable UEFI shim bootloaders remained trusted for years, allowing attackers to bypass Secure Boot for persistent malware and rootkit deployment.
Advertisement