Rootkit
Malware that hides deep in the operating system and stays invisible to traditional antivirus scanners.
A rootkit hides deep in the operating system (kernel mode or bootloader) and stays invisible to traditional scanners – other malware can use it as cover. Rootkit removal often requires a boot scan before the OS starts.
Most modern suites (Kaspersky, Bitdefender) offer dedicated rootkit scanning.
Why this matters in 2026
UEFI rootkits like BlackLotus and CosmicStrand are the most dangerous variant in 2026: they nest themselves before the operating system starts and survive reinstalls. Detection requires dedicated UEFI scanners (Kaspersky Rescue, ESET SysRescue). Main distribution path: fake BIOS updates on compromised websites.
How to protect yourself
Enable Secure Boot in UEFI; download BIOS/UEFI updates only directly from the vendor (Asus, MSI, Gigabyte, HP, Dell, etc.) – never from Google results. If you suspect a rootkit: scan via an antivirus rescue medium (Kaspersky Rescue Disk, ESET SysRescue) instead of from the running system.