In this post, we're drawing a parallel between Drovorub and early reported rootkit, analyzing ability to conceal C2 traffic with Netfilter hook.
We also conduct an experiment by loading a malicious kernel-mode rootkit into the host via a Docker container
prevasio.io/blog/drovorubs-a…