OBSCURE#BAT Malware Highlights Risks of API Hooking
ID: 8fd0b7d9-ff16-5ac5-a14c-141197d0f8ad
STIX ID: report--8fd0b7d9-ff16-5ac5-a14c-141197d0f8ad
Feed Name: Dark Reading
OBSCURE#BAT is a malware campaign that lures victims with fake captchas and software updates to execute obfuscated batch scripts and PowerShell payloads which ultimately deploy the r77 user‑mode rootkit; r77 uses API hooking to cloak files, registry entries, and processes, making detection difficult. Securonix observed English‑language lures and US‑based infrastructure, recommended defenses include reviewing batch files before execution, enabling Sysmon and PowerShell logging, and combining EDR with SIEM for improved detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
