Skip to main content

Rootkits - Stealthy Malware Deep in Your OS

About 2 min read

A rootkit is malware that lurks deep within a system and hides its own presence from the OS and security software. The name derives from "root," the highest privilege in Unix/Linux, and attackers use it to maintain persistent access to a system. Because it is extremely difficult to detect, there are cases where information is stolen over long periods without the infection ever being noticed. In 2024, several new variants of UEFI rootkits were discovered, heightening the importance of firmware-level security measures.

Why Absence from a List Is Not Evidence

A process list or a list of network connections merely displays the answers returned by a query to the operating system. A rootkit embedded in the kernel sits in a position where it can rewrite the response to that query itself, so it can arrange for the rows about itself not to be returned. In that case, the absence of suspicious entries from a list is not evidence that nothing suspicious exists. It is a state in which the instrument of observation is controlled by the object being observed, and a result that looks normal cannot be distinguished from things actually being normal. Where a rootkit is suspected, observation therefore has to be switched to methods that do not go through the operating system. Acquiring and analyzing the contents of memory directly, examining the disk from an environment booted from separate media, and recording traffic on the network side all share the property of not asking the compromised operating system for the answer. Before judging whether something was detected, a step is needed to confirm where that information came from.

The Hiding Structure of Rootkits

UEFI/firmware layer (bootkit) - cannot be removed even by reinstalling the OS
Kernel layer (kernel mode) - the hardest to detect
User layer (user mode) - hides processes and files
Application layer - the layer where ordinary security software runs

Types of Rootkits

Kernel-mode rootkits are embedded in the OS kernel and are the hardest to detect. User-mode rootkits run at the application layer, hiding processes and files. Bootkits infect the OS boot process and begin operating before the OS is loaded. UEFI rootkits infect the firmware, making them the most troublesome type, as they cannot be removed even by reinstalling the OS.

Why Discovery Is Delayed

What makes a rootkit troublesome is less the scale of the damage than the route by which it is discovered. Monitoring usually depends on the information that the machine under examination reports about itself. If the process list and the traffic view have been rewritten, the monitoring screen keeps showing "nothing unusual," and as time passes the traces of the intrusion are overwritten and become harder to follow. Discovery therefore tends to be triggered by information arriving from outside the system: a remark from a party the machine communicates with, a notice from a business partner, or leaked data found elsewhere. If an opening for re-entry such as a backdoor remains, the intruder returns by the same route even after the rootkit appears to have been removed. In incident response, the work has to proceed on the premise that what the machine reports cannot be trusted, cross-checking against separate evidence such as network-side records.

Detection and Removal

Because ordinary virus scans cannot detect them, dedicated rootkit detection tools or scanning from outside the OS (booting from bootable media) are necessary. If a kernel-mode rootkit is confirmed, a clean reinstall of the OS is the most reliable countermeasure. As preventive measures, keeping the OS and software up to date, protecting administrator accounts with strong random passwords, and enabling multi-factor authentication can reduce the risk of initial intrusion.

Related Terms

Was this article helpful?