r77

Aliases: r77 Rootkit

Malware type
rootkit
Profile updated
2026-07-07 14:31:27

Context

According to the author, r77 is a ring 3 rootkit that hides everything: * Files, directories * Processes & CPU usage * Registry keys & values * Services * TCP & UDP connections * Junctions, named pipes, scheduled tasks

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_R77 (yara-rule)

Reports & references

  • harfanglab.io — Unpacking Packxor (report)
  • securonix.com — Analyzing Obscurebat Threat Actors Lure Victims Into Executing Malicious Batch Scripts To Deploy Stealthy Rootkits (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.R77 (report)
  • twitter.com — 1523179260273254407 (report)
  • github.com — R77 Rootkit (report)

External references