Rootkits
Rootkits have been available since the 90s and are widely used. Rootkits are tools that have the following capabilities:
- Have a backdoor into the target system
- Keep it hidden that the target system is compromised or infected
The main use of rootkits is to infect the operating system itself, and thus they are one of the most effective backdoors as they hide everything from end users or system admins.
The name refers to root and kit as the first variants of these tools targetted Linux/Unix systems to get root (superuser) access. However, the first known variant that targeted Windows was in 1999, and macOS in 2009.
Some rootkits allow you to gather information about the target system and even through the local network. In recent years, rootkits have included spyware and bots in their packages.
There are multiple common modes for these rootkits:
- User mode: In this mode, the rootkit modifies legitimate system files and processes to hide its presence...