Rootkit 

Advanced Espionage Tool  Adware  AI  Android  APP  APPX file  ATM Malware  Backdoor  Banking  Bookit  Bot  BotNet  Code-injection  CoinMiners  Crypt  Cryptocurrency  Cryptojacking  CyberSpy  Data Wiper  DDoS  DEAMON  Destructive Malware  DNS Backdoor  Downloader  Driver  Droper  EDR and AV Killer  ELF   ENGINE  Espionage  Exploit  Families  Fileless  FRAMEWORK  FUD Engine  Go  GPT  GPU  GRU Malware  HTML  ICS  InfoStealer  Injector  iOS  IoT  IRC  ISS   Java  JavaScipt  JSON  Keylogger  Killer  Kit  LINUX  Loader  Maas  MacOS  Macro  Malware  Military Malware  Miner  Mobil  MultiOS  nmp  OS  OSX   OT malware  P2P virus  Password STEALER  Pay-per-install (PPI)  PoS Malware  PowerShell  Program  PyPI   Python  QR trojan  Ransom  Raspberry  RAT  Roque  Rootkit  SMS  Spy  Spyware  SQL Malware  Stealer  SymbOS  Tool  Trojan  TV  UEFI bootkit  USB  Utility  VBA Macro  VBE  VBS  VHD malware  Virus  Vishing toolset  VMware ESXi  Windows  Wipper  WM virus  Worm  Wrapper 

17.10.25

LinkPro

LinkPro: eBPF rootkit analysis

MALWARE

Rootkit

24.04.25

io_uring

io_uring Is Back, This Time as a Rootkit

MALWARE

ROOTKIT

09.04.25

TCESB

How ToddyCat tried to hide behind AV software

MALWARE

Rootkit

14.03.25

OBSCURE#BAT

Analyzing OBSCURE#BAT: Threat Actors Lure Victims into Executing Malicious Batch Scripts to Deploy Stealthy Rootkits

MALWARE

Rootkit

27.02.25

CleverSoar

New “CleverSoar” Installer Targets Chinese and Vietnamese Users

MALWARE

Rootkit

18.02.25

PRIVATELOG 

A loader that's used to drop Winnti RAT (aka DEPLOYLOG) which, in turn, delivers a kernel-level rootkit named WINNKIT by means of a rootkit installer

MALWARE

Rootkit

18.02.25

WINDJAMMER 

A rootkit with capabilities to intercept TCPIP Network Interface, as well as create covert channels with infected endpoints within intranet

MALWARE

Rootkit

13.12.24

PUMAKIT 

PUMAKIT is a sophisticated loadable kernel module (LKM) rootkit that employs advanced stealth mechanisms to hide its presence and maintain...

MALWARE

ROOTKIT

25.11.24

GHOSTENGINE 

When Guardians Become Predators: How Malware Corrupts the Protectors

MALWARE

ROOTKIT

19.07.24

Demodex 

A Comprehensive Look at the Updated Infection Chain of Ghost Emperor’s Demodex Rootkit. 

MALWARE

Rootkit

02.02.24

BPFdoor

We discuss proof-of-concept rootkits and malware used by cybercriminals in conjunction with Berkeley Packet Filtering (BPF), ....

MALWARE

Rootkit

05.10.23

r77

According to the author, r77 is a ring 3 rootkit that hides everything: * Files, directories * Processes & CPU usage * Registry keys & values *
Services * TCP & UDP connections * Junctions, named pipes, scheduled tasks

MALWARE

Rootkit

13.07.23

FiveSys

Digitally-Signed Rootkits are Back – A Look at FiveSys and Companions

MALWARE

Rootkit

24.06.23

BlackLotus

BlackLotus stage 2 bootkit-rootkit analysis

MALWARE

Rootkit

09.01.23

Gootkit

We analyzed the infection routine used in recent Gootkit loader attacks on the Australian healthcare industry and found that Gootkit leveraged
 SEO poisoning for its initial access and abused legitimate tools like VLC Media Player. 

MALWARE

Rootkit

16.06.22

Sality

Modern Sality variants also have the ability to communicate over a peer-to-peer (P2P) network, allowing an attacker to control a botnet of
Sality-infected machines. 

MALWARE

Rootkit/Backdoor