Elastic Security Labs steps through the r77 rootkit
ID: 458e2e8b-d754-5ece-b6f2-6dfdc2b0a718
STIX ID: report--458e2e8b-d754-5ece-b6f2-6dfdc2b0a718
Feed Name: Elastic Security Labs
Elastic Security Labs analyzes a stealthy campaign deploying the open-source r77 userland rootkit to hide and persistently install the XMRig crypto miner across systems in multiple Asian countries; the report details the install/stager/service/core modules, AMSI bypass, API unhooking, process hollowing with parent PID spoofing, registry- and scheduled-task-based persistence, included YARA detection rules, and provides IoCs (malicious domain, IPs, and multiple SHA-256 hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
