r77 is an open-source Windows user-mode rootkit created by bytecode77. It is designed to conceal attacker-controlled activity by intercepting Windows API calls and filtering results returned to user-mode tools. Its core component can hide configured processes, files, registry entries, services, network-related artifacts, scheduled tasks, and CPU-usage information; proof-of-concept implementations commonly hide artifacts using a designated filename prefix. r77 has been incorporated into cryptomining, botnet, information-stealing, and trojanized-software campaigns, as well as modified variants delivered through ClickFix operations. The rootkit architecture comprises installer, stager, service, and core modules. Observed deployments have used AMSI bypasses, restoration of clean in-memory system-library code to evade user-mode hooks, PPID spoofing, process hollowing, and injection of the core DLL into running and newly created processes. Persistence mechanisms observed in r77-based deployments include SYSTEM-level scheduled tasks, Windows services, and registry-resident stagers. r77 targets Windows systems and is primarily used for defense evasion and persistence rather than as a standalone payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Necro downloads x86.dll or x64.dll corresponding to the open-source r77-rootkit project, then loads it through shellcode and process injection.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The installer creates a scheduled task to execute the PowerShell command using COM objects; the task is configured to execute at startup with the SYSTEM account.
The third script also creates a .cmd file in the Windows startup folder, naming it after the user’s hostname, and schedules a system restart. After the device restarts, the .cmd file launches a large DLL through rundll32.exe and attempts to deliver the final payload.
The ClickFix technique attempts to trick users into running malicious commands on their devices... It typically gives the users instructions that involve clicking prompts and copying, pasting, and running commands directly in the Windows Run dialog box, Windows Terminal, or Windows PowerShell.
The installer creates a scheduled task to execute the PowerShell command using COM objects; the task is configured to execute at startup with the SYSTEM account.
One of the primary tasks of the service module is to inject the rootkit's core into every running process on the system.
The malware leverages the process hollowing technique to inject its payload into a legitimate-looking Microsoft process ... either C:\Windows\System32\dllhost.exe or C:\Windows\SysWow64\dllhost.exe.
The rootkit’s core hooks multiple Windows APIs ... By filtering the output of the Windows APIs, the core module is able to selectively hide specific files, processes, or registry keys from the system's users and security tools.
The PowerShell command is then obfuscated by replacing variable names with random strings.
It’s often combined with delivery vectors such as phishing, malvertising, and drive-by compromises, most of which even impersonate legitimate brands and organizations... recent ones spoof Google’s reCAPTCHA and Cloudflare’s Turnstile solution. We’ve even observed threat actors spoof social media platforms like Discord.
One of the primary tasks of the service module is to inject the rootkit's core into every running process on the system.
The malware leverages the process hollowing technique to inject its payload into a legitimate-looking Microsoft process ... either C:\Windows\System32\dllhost.exe or C:\Windows\SysWow64\dllhost.exe.
The stager module next attempts to obtain the SeDebugPrivilege which allows it to inspect and adjust the memory of other processes.
The malware first gets the process ID of the running winlogon.exe process ... [and] set[s] the parent process handle via the PROC_THREAD_ATTRIBUTE_PARENT_PROCESS attribute.
These final payloads are often 'fileless'... they’re loaded and launched in memory by living-off-the-land binaries (LOLBins)... we’ve observed its code injected into LOLBins, such as msbuild.exe, regasm.exe, or powershell.exe.
The rootkit uses MinHook to redirect WinAPI calls, so that it hides processes and file names, e.g., from explorer and taskmanager.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source Windows rootkit used here via a stager to bypass AMSI, inject hooking DLLs into winlogon.exe, hide processes/files/registry keys with the $77 prefix, and maintain persistence through registry storage and a Windows service.
Rootkit component referenced as part of the analyzed malware's stealth and persistence toolkit.
Open-source rootkit used to cloak files/registry keys/tasks and provide stealth/persistence; deployed in the OBSCURE#BAT campaign.
r77 is a rootkit family used in ClickFix and FileFix campaigns to hide malware processes and maintain persistence on infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.