logo

Elastic Security Labs steps through the r77 rootkit

ID: 458e2e8b-d754-5ece-b6f2-6dfdc2b0a718

STIX ID: report--458e2e8b-d754-5ece-b6f2-6dfdc2b0a718

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2023-05-22

Date Updated: 2026-04-27

...
...

Elastic Security Labs analyzes a stealthy campaign deploying the open-source r77 userland rootkit to hide and persistently install the XMRig crypto miner across systems in multiple Asian countries; the report details the install/stager/service/core modules, AMSI bypass, API unhooking, process hollowing with parent PID spoofing, registry- and scheduled-task-based persistence, included YARA detection rules, and provides IoCs (malicious domain, IPs, and multiple SHA-256 hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.