CYBERSECURITYTRACKER
TRACKING7,194 stories in this site build1,511 vulnerability news stories in this site build
Permanent story citation

Elastic Security Labs steps through the r77 rootkit

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7927

As cited

Copy frozen at (site build).

threat intel

Elastic Security Labs steps through the r77 rootkit

Elastic Security Labs analyzed a campaign using the r77 rootkit, which has been observed deploying the XMRIG cryptocurrency miner. The research documented the rootkit's modular components and their role in delivering additional malicious payloads.

Why it matters: Security teams should understand r77's capabilities and deployment chain to detect and respond to infections that may establish persistence and launch cryptomining or follow-on attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary