HDRoot

First seen
2015-03-01 00:00:00
Malware type
rootkit
Family
Malware family
Profile updated
2026-07-07 15:05:08

Context

HDRoot is a sophisticated rootkit known for its persistence mechanisms, often used by advanced threat actors. It can hide its malicious activities by manipulating filesystem and process information, making detection difficult.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Hdroot (report)
  • Kaspersky — 72356 (report)
  • Kaspersky — 72275 (report)

External references