As cited
Copy frozen at (site build).
threat intel
Elastic Security Labs steps through the r77 rootkit
Elastic Security Labs analyzed a campaign using the r77 rootkit, which has been observed deploying the XMRIG cryptocurrency miner. The research documented the rootkit's modular components and their role in delivering additional malicious payloads.
Why it matters: Security teams should understand r77's capabilities and deployment chain to detect and respond to infections that may establish persistence and launch cryptomining or follow-on attacks.
- Source published
- First seen by Cybersecurity Tracker