
Image courtesy of Sophos
By Scott Aurnou
‘Rootkit’ is a term used to describe stealthy – and frequently malicious – software that can give an attacker complete control over a system while remaining effectively invisible to a legitimate computer user or system administrator. One way to think of it might be like an unseen intruder able to wander though your home or office at will. A disconcerting image, to be sure. The name ‘rootkit’ comes from the term ‘root’ access, which in turn describes administrative or ‘superuser’ access on the older Unix computer operating system. Someone with root access effectively has system-wide control. This can be used to cause significant damage to a computer or network, though rootkits are generally geared towards stealth – they are more likely to alter other software running in the system to prevent detection and conceal themselves. This makes many of them very difficult to detect.
There are legitimate uses for rootkits – such as employer or parental monitoring software – though many of them are malicious.
What kind of damage can a rootkit cause? While the degree of access and control to a target computer depends upon where it is embedded in a system, a well-placed rootkit can do just about anything to a target computer. This includes hiding other malware from detection by security software and/or creating easy access (usually via a ‘backdoor’ in the target system) for the rootkit or other malware to surreptitiously spy on computer users, steal data, sabotage system resources or remotely control the computer for use in a botnet.
Read more ›


