OBSCURE#BAT is a malware delivery campaign associated with ClickFix-style social engineering and the deployment of a modified version of the open-source r77 rootkit. The campaign has been linked to fake verification or challenge pages, including Discord-themed lures, that trick users into manually executing malicious commands. This tradecraft aligns with broader ClickFix activity in which victims are induced to copy and run commands through Windows utilities such as Run or PowerShell, enabling fileless or low-file-footprint execution and evasion. High-confidence reporting ties OBSCURE#BAT specifically to delivery of r77 rootkit. In the observed activity, the campaign relied on spoofed web content and user-driven execution rather than an exploit chain, indicating an emphasis on social engineering for initial access. Because the available evidence is limited to campaign attribution around ClickFix landing pages and r77 delivery, additional details about operator identity, organizational structure, victimology, geographic origin, and broader post-compromise objectives are currently not available at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.