Last seven days
- First activity
- Sep 8, 2026
- Last activity
- Sep 8, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
r77 is an open-source Windows Ring 3 rootkit created by bytecode77.
Profile source: Mallory opens in a new tabr77
r77 is an open-source Windows Ring 3 rootkit created by bytecode77. It uses API hooking to conceal selected processes, files, registry entries, network connections, scheduled tasks, and CPU usage from user-mode tools. r77 variants commonly identify objects for concealment through a designated name prefix and use injected hooking DLLs to apply hiding behavior across processes. Threat actors have deployed r77 for defense evasion and persistence, including through application-initialization mechanisms, service-based installation, and reflective process injection. Observed campaigns have incorporated modified r77 variants as post-compromise components, including Necro botnet activity, Osno malware, and ClickFix campaigns attributed to OBSCURE#BAT. r77 has also been deployed alongside malware loaders, remote-access tools, and infostealers to make infections more difficult to detect and remediate.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Necro downloads x86.dll or x64.dll corresponding to the open-source r77-rootkit project, then loads it through shellcode and process injection.
MITRE ATT&CK
Reporting
Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.