Skip to content

r77

r77 is an open-source Windows Ring 3 rootkit created by bytecode77.

Profile source: Mallory opens in a new tab

r77

Family profile

r77 is an open-source Windows Ring 3 rootkit created by bytecode77. It uses API hooking to conceal selected processes, files, registry entries, network connections, scheduled tasks, and CPU usage from user-mode tools. r77 variants commonly identify objects for concealment through a designated name prefix and use injected hooking DLLs to apply hiding behavior across processes. Threat actors have deployed r77 for defense evasion and persistence, including through application-initialization mechanisms, service-based installation, and reflective process injection. Observed campaigns have incorporated modified r77 variants as post-compromise components, including Necro botnet activity, Osno malware, and ClickFix campaigns attributed to OBSCURE#BAT. r77 has also been deployed alongside malware loaders, remote-access tools, and infostealers to make infections more difficult to detect and remediate.

Capabilities

  • Defense Evasion
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 8, 2026
Last activity
Sep 8, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • DZ1

Leading providers

  • Telecom Algeria1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Keksec

Necro downloads x86.dll or x64.dll corresponding to the open-source r77-rootkit project, then loads it through shellcode and process injection.

MITRE ATT&CK

r77 in ATT&CK

9 distinct techniques

Reporting

Research mentioning r77

Jul 31
Malware News

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators

Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Jul 31
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

Aug 21
Microsoft Security

Think before you Click(Fix): Analyzing the ClickFix social engineering technique | Microsoft Security Blog

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.