r77
Aliases: r77 Rootkit
- Malware type
- rootkit
- Profile updated
- 2026-07-07 14:31:27
Context
According to the author, r77 is a ring 3 rootkit that hides everything: * Files, directories * Processes & CPU usage * Registry keys & values * Services * TCP & UDP connections * Junctions, named pipes, scheduled tasks
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_R77 (yara-rule)
Reports & references
- harfanglab.io — Unpacking Packxor (report)
- securonix.com — Analyzing Obscurebat Threat Actors Lure Victims Into Executing Malicious Batch Scripts To Deploy Stealthy Rootkits (report)
- malpedia.caad.fkie.fraunhofer.de — Win.R77 (report)
- twitter.com — 1523179260273254407 (report)
- github.com — R77 Rootkit (report)