Full Report
2025-03-13 • Securonix • Den Iyzvyk, Tim Peck • win.quasar_rat, win.r77 Open article on Malpedia
Analysis Summary
The provided text is a citation/metadata block for an article and does not contain sufficient narrative detail to populate all required sections of the threat actor summary (History, Detailed TTPs, Targeting specifics, Motivations, and deep Tooling).
Therefore, the summary will be generated based only on the explicit information discoverable within the provided context block, which primarily identifies the actor and associated tools.
***
# Threat Actor: OBSCURE#BAT
## Attribution & Identity
The threat actor is identified as **OBSCURE#BAT**. The analysis reporting on this actor was conducted by the organization **Securonix**.
## Activity Summary
The article focuses on analyzing OBSCURE#BAT activity where the threat actors lure victims into executing malicious batch scripts which subsequently deploy stealthy rootkits.
## Tactics, Techniques & Procedures
- Luring victims into executing **malicious batch scripts**.
- Deployment of **stealthy rootkits** following script execution.
## Targeting
- **Sectors:** Not specified in the provided context.
- **Geography:** Not specified in the provided context.
- **Victims:** Not specified in the provided context.
## Tools & Infrastructure
- **Malware families used:**
- win.quasar_rat
- win.r77 (Identified as a deployed rootkit based on the context description)
- **Infrastructure (C2, domains, IPs):** None specified in the provided context.
## Implications
OBSCURE#BAT utilizes batch scripts for initial execution, leading to the installation of rootkits, suggesting a goal focused on deep system persistence and stealth.
## Mitigations
Specific, detailed mitigations are not detailed in the provided context. General mitigation should focus on scrutinizing the execution of batch scripts from untrusted sources.