216.73.216.6

Analyzing OBSCURE#BAT: Threat Actors Lure Victims into Executing Malicious Batch Scripts to Deploy Stealthy Rootkits

· Published 13/04/2025 10:37 · Modified 14/04/2025 12:17

Export JSON

Essential information

Published
13/04/2025 10:37
Modified
14/04/2025 12:17
Tags
2025-04-13 api hooking quasarrat r77 rootkit social engineering user-mode rootkit
Related entities
2 malware

Description

A stealthy malware campaign dubbed OBSCURE#BAT has been discovered, utilizing and deceptive file downloads to trick users into executing obfuscated code. The infection chain deploys a that manipulates system processes and registry entries to evade detection and maintain persistence. The malware, identified as , hides files, processes, and registry keys with a specific prefix. It uses highly obfuscated batch scripts, PowerShell commands, and registry manipulation to establish persistence. The campaign targets English-speaking individuals through fake captchas, malvertising, and masquerading as legitimate software. The rootkit's ability to cloak malicious activities and inject into critical system processes makes it particularly dangerous and difficult to detect using conventional methods.

External references