Detection and Removal of the Syslogk Rootkit in a Linux Environment

Detection and Removal of the Syslogk Rootkit in a Linux Environment

1. Overview The AhnLab SEcurity intelligence Center (ASEC) continuously monitors various threats targeting Linux environments. Techniques that modify the Linux kernel to conceal malware and signs of compromise have been used for a long time, and Syslogk is one such rootkit that operates in this manner. This document provides an