EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium
A security analyst is performing incident response after a critical database server was found to be infected with malware. During the forensic analysis, the analyst discovers that the malware has modified the system's kernel to redirect system calls and hide its processes and files from standard operating system utilities. This sophisticated technique makes it very difficult for administrators to detect and remove the malicious software. Which type of malware is most likely responsible for this compromise?
- ATrojan Horse
- BRootkit
- CAdware
- DWorm
Show answer & explanationAnswer & explanation
Correct answer: B. Rootkit
A rootkit is a collection of malicious software designed to enable access to a computer or an area of its software that is not otherwise allowed, while simultaneously hiding its existence or the existence of other malware. Modifying the kernel and redirecting system calls to hide processes and files are classic rootkit behaviors.
Why the other options are wrong
- A. A Trojan horse disguises itself as legitimate software but doesn't primarily focus on hiding its presence through kernel modifications.
- C. Adware displays unwanted ads and does not typically modify the kernel to hide itself.
- D. A worm is self-replicating malware, but its primary function isn't hiding its presence by kernel modification.
Rootkit
A type of malicious software designed to gain and maintain privileged access to a computer while actively hiding its presence from administrators.
- Operates at a low level (kernel mode).
- Modifies OS functions to hide files, processes, and network connections.
- Difficult to detect and remove.
Memory trick: Rootkits Rule the Kernel, Keeping Secrets.