logo

OBSCURE#BAT Malware Highlights Risks of API Hooking

ID: 8fd0b7d9-ff16-5ac5-a14c-141197d0f8ad

STIX ID: report--8fd0b7d9-ff16-5ac5-a14c-141197d0f8ad

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-03-13

Date Updated: 2026-04-21

Author: Rob Wright

...
...

OBSCURE#BAT is a malware campaign that lures victims with fake captchas and software updates to execute obfuscated batch scripts and PowerShell payloads which ultimately deploy the r77 user‑mode rootkit; r77 uses API hooking to cloak files, registry entries, and processes, making detection difficult. Securonix observed English‑language lures and US‑based infrastructure, recommended defenses include reviewing batch files before execution, enabling Sysmon and PowerShell logging, and combining EDR with SIEM for improved detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.