EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium
A security analyst is investigating a compromised workstation that exhibits unusual network traffic patterns, including frequent connections to a remote IP address on an uncommon port. The workstation's CPU usage is also consistently high, even when idle. Further investigation reveals a hidden process running in the background. Which type of malware is most likely responsible for these observations?
- AAdware
- BRootkit
- CSpyware
- DRansomware
Show answer & explanationAnswer & explanation
Correct answer: B. Rootkit
The combination of hidden processes, unusual network activity, and high CPU usage strongly suggests a rootkit, which is designed to conceal its presence and often uses system resources for malicious activities like cryptocurrency mining or botnet participation.
Why the other options are wrong
- A. Adware primarily displays unwanted advertisements and typically doesn't involve hidden processes or high CPU usage for covert operations.
- C. While spyware monitors user activity, it doesn't inherently hide its processes at a deep system level like a rootkit or cause sustained high CPU usage for its primary function.
- D. Ransomware primarily encrypts files and demands a ransom, usually not focusing on hiding its presence or sustained high CPU usage.
Rootkit
A type of malicious software designed to hide its presence and maintain privileged access to a computer while concealing its existence from the user and other system processes.
- Operates at a deep system level (kernel or user mode).
- Hides files, processes, and network connections.
- Can be used to install other malware or facilitate persistent access.
Memory trick: Rootkits hide deep to control the system's core.