root
- Malware type
- rootkit
- Family
- Malware family
- Last IoC activity
- 2026-06-15 14:00:04
- Profile updated
- 2026-07-07 14:01:13
Context
The 'root' malware is a type of rootkit often used to gain unauthorized access and maintain stealthy control over a compromised system. It is commonly used to hide other malicious activities and tools from detection, making it harder for security solutions to identify and remove. Without specific targeting information, it is considered a general threat.
Detection coverage
- 2 YARA rules
Detection rules
- SIGNATURE_BASE_EXPL_LOG_Commvault_CVE_2025_57791_Indicator_Shell_Drop_Aug25 (yara-rule)
- SIGNATURE_BASE_SUSP_ENV_Folder_Root_File_Jan23_1 (yara-rule)
Reports & references
- ransomlook.io — Root (report)