r77 rootkit is a Windows user-mode rootkit used to conceal malicious processes, files, and Registry entries. Modified variants have been deployed as injected DLLs by the cross-platform Necro bot and in altered XWorm builds. These variants hook native Windows functions in ntdll.dll to filter process, directory, and Registry enumeration results, providing defense evasion for malware components marked with designated name prefixes. r77 has also been delivered as a final-stage payload through ClickFix campaigns, including Discord-themed lures. It has been bundled with XMRig cryptomining payloads and protected by PackXOR in some observed operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Necro will then load the rootkit using a piece of shellcode using process injection from another open source project, sRDI; the code calls OpenProcess, VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread.
Necro downloads x86.dll or x64.dll, corresponding to the open-source r77-rootkit project, which hides files, directories, processes, registry items, connections, and other entities.
Inside, it wraps the legitimate JDownloader installer alongside an XOR-encrypted second-stage PE... Stage 2's strings are all XOR-obfuscated with the same fywo key used for its resources.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rootkit payload delivered in ClickFix campaigns (including Discord-themed lures) to provide stealth/persistence on compromised hosts.
Rootkit installed by a leaked/modified XWorm plugin to hide processes prefixed with "$CRX".
Rootkit component observed bundled with XMRig in samples protected by PackXOR (and additionally obfuscated with SilentCryptoMiner in described cases).
Referenced as a rootkit bot involved in a JDownloader supply-chain attack and described as disabling antivirus software.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.