EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium

A security analyst is investigating a compromised workstation that exhibits unusual network traffic patterns, including frequent connections to a remote IP address on an uncommon port. The workstation's CPU usage is also consistently high, even when idle. Further investigation reveals a hidden process running in the background. Which type of malware is most likely responsible for these observations?

  1. AAdware
  2. BRootkit
  3. CSpyware
  4. DRansomware
Show answer & explanation

Correct answer: B. Rootkit

The combination of hidden processes, unusual network activity, and high CPU usage strongly suggests a rootkit, which is designed to conceal its presence and often uses system resources for malicious activities like cryptocurrency mining or botnet participation.

Why the other options are wrong

  • A. Adware primarily displays unwanted advertisements and typically doesn't involve hidden processes or high CPU usage for covert operations.
  • C. While spyware monitors user activity, it doesn't inherently hide its processes at a deep system level like a rootkit or cause sustained high CPU usage for its primary function.
  • D. Ransomware primarily encrypts files and demands a ransom, usually not focusing on hiding its presence or sustained high CPU usage.

Rootkit

A type of malicious software designed to hide its presence and maintain privileged access to a computer while concealing its existence from the user and other system processes.

  • Operates at a deep system level (kernel or user mode).
  • Hides files, processes, and network connections.
  • Can be used to install other malware or facilitate persistent access.

Memory trick: Rootkits hide deep to control the system's core.

More Malware Threats questions