Learn about Zero Trust Architecture
Impenetrable cybersecurity without sacrificing usability
Gain detailed visibility into all your endpoints activities
Harden applications and hardware environments
Immediate and continuous response to incidents
Close the window of time your data could be exposed
Get your Comodo solutions setup, deployed or optimized
Control access to malicious websites
Defend from any internet based threats
Stop email threats before it enters your inbox
Preserve and protect your sensitive data
Keep your website running fast and malware free
Add encryption to your websites
Automated certificate mgmt. platform
Secure private intranet environments
Digital signature solutions for cloud apps
Encrypt emails for senders and recipients
Stay compliant with PCI DSS
Trusted authentication for IoT devices
Francisco Partners a leading technology-focused private equity fund, has acquired a majority stake in Comodo’s certificate authority business. Newly renamed from Comodo CA Limited to Sectigo Limited. Privacy Policies, Trademarks, Patents and Terms & Conditions are available on Sectigo Limited’s web site.
Meet the people behind the direction for Comodo
Get the latest news about Comodo
People are the key to achievement and prosperity
Stay up to date with our on-demand webinars
Worldwide: Sales, Support and General Inquiries
Schedule a live demonstration of our solutions
Need immediate help? Call 1-888-551-1531
Instantly removes viruses to keep your PC virus free
Experience true mobile security on your mobile apple devices
Secure Internet Browser based on Chrome
Chrome browser internet security extension
Submit a ticket to our support team
Share any product bugs or security flaws
Collaborate with research experts on data sets
Valkyrie Threat Intelligence Plugins
Valkyrie Threat Intelligence APIs
The security engineers and IT experts from the Comodo Labs are constantly analyzing the thousands of malware families that are trying to cause destruction and chaos to IT infrastructures large and small – and ensuring the customers of Comodo stay protected and secure from these malware families.
In an ongoing series of posts here at blogs.comodo.com, the security experts at Comodo will look at a specific malware family and stack it up against Comodo’s advanced endpoint protection and containment technology, and talk about the how and why Comodo’s technology defeats all malware. Comodo Senior Vice President of Engineering Egemen Tas and Director of Threat Research Igor Demihovskiy offered their perspectives for this week’s post to Senior Product Marketing Manager Paul Mounkes.
How do Rootkits work?
Rootkits are considered by many to be a category of malware, but they’re different in that they don’t actually conduct malicious activity on their own. Rather, they attempt to hide themselves and their payload from detection, and provide unlimited access to the host system.
There are many types of rootkits, each one worse than the last. The ZeroAccess rootkit gained system entry by injecting its code into Adobe Flash Player updates. When a UAC message warned the system user of the access request, the user would almost always allow it because it looked to be coming from a trusted source, Adobe. And since most users run in administrator mode, ZeroAccess immediately had the root-level system access it needed.
Advanced rootkits like ZeroAccess run at the kernel level which gives them unlimited access to all system resources. Others hide themselves in firmware or bootcode so that, even if they are found inside the OS and deleted, they will re-install themselves the next time the system boots up.
What do Rootkits do?
The goal is always the same; to mask behavior so the truly malicious files can operate without having to contend with antiviruses. ZeroAccess uses aggressive self-defense techniques like disabling antivirus programs, reconfiguring security settings, altering processes and/or disabling logging, among other things.
If a rootkit is running on your system, you cannot trust your computer’s detection, alerting and/or logging systems (your antivirus program cannot trust them either) because malicious behavior is hidden. As a result, your computer is not only lying to you, in a sense it’s lying to itself. And all the while, malware is stealing your login codes, or using your computing resources without your permission.
Because of this, it is extremely difficult to remove a rootkit once it’s installed. In many cases, wiping the hard drive and reinstalling the OS could be the only option.
Prevention with Comodo is the key
Since it can be impossible to eliminate rootkits once they are installed, the key is to stop them from ever installing in the first place. Because their droppers disguise what they’re doing in so many devious ways, there’s only one reliable way to deal with them.
With Comodo Advanced Endpoint Protection, the installer is forced to run in secure containment. All contained executables are denied any direct access to the system’s hard drive, and can only interact with virtual processes. They are never allowed administrator access, so they cannot install at the kernel level.
While running in containment, the files are subjected to Comodo’s multi-layered local and cloud-based malware analysis. If necessary, Comodo’s cloud-based specialized threat analysis and protection layer (STAP) can even request expert human intervention. Once a Known Bad verdict is returned, the virtual container is deleted like nothing ever happened.
If you feel your company’s IT environment is under attack from phishing, malware, spyware or cyberattacks, contact the security consultants at our Comodo Labs: https://enterprise.comodo.com/contact-us.php
Related Resources:
Tags: malware
Reading Time: 4 minutes Increased dependency on computers and access to data makes an organization more vulnerable to cybersecurity threats. With the increase in cyber-criminals and cyber-attacks, many companies today are looking for greater protection of their decentralized computing work environments from their Managed Service Providers (MSPs). As a result, MSPs need to deliver firewall solutions that are designed…
Reading Time: 3 minutes Rapid technological growth and increasing digitalization in all aspects of life around the world have increased the value of ensuring cyber-security at all levels. This is increasingly true for EU member states and the organizations that are based in or operate from these countries. The number of cyber-attacks targeting EU member states has risen. The…
Reading Time: 3 minutes Disruptions are often unforeseen. This could be a catastrophic event like a hurricane, a fire, or an earthquake. Disruptions, however, can also come in other forms such as that of a pandemic. This means that a building doesn’t necessarily have to be demolished or lives have to be lost for an unforeseen event to completely…
Sign up to our cyber security newsletter
Comodo Cybersecurity would like to keep in touch with you about cybersecurity issues, as well as products and services available. Please sign up to receive occasional communications. As a cybersecurity company, we take your privacy and security very seriously and have strong safeguards in place to protect your information.
agreecheck
See how your organization scores against cybersecurity threats
Advanced Endpoint Protection, Endpoint Detection and Response Built On Zero Trust Architecture available on our SaaS EPP