root

Malware type
rootkit
Family
Malware family
Last IoC activity
2026-06-15 14:00:04
Profile updated
2026-07-07 14:01:13

Context

The 'root' malware is a type of rootkit often used to gain unauthorized access and maintain stealthy control over a compromised system. It is commonly used to hide other malicious activities and tools from detection, making it harder for security solutions to identify and remove. Without specific targeting information, it is considered a general threat.

Detection coverage

  • 2 YARA rules

Detection rules

  • SIGNATURE_BASE_EXPL_LOG_Commvault_CVE_2025_57791_Indicator_Shell_Drop_Aug25 (yara-rule)
  • SIGNATURE_BASE_SUSP_ENV_Folder_Root_File_Jan23_1 (yara-rule)

Reports & references

  • ransomlook.io — Root (report)

External references