Alpha Cyber

R is for Rootkit: Securing Against Advanced Cyber Threats by Mapping the R77 Rootkit

In the ever-evolving world of cybersecurity, advanced threats like rootkits remain among the most dangerous. One such example is the R77 Rootkit, a highly sophisticated malware that stealthily infiltrates systems and provides backdoor access to cybercriminals.

Alpha Cyber Research3 min readupdated 1 Apr 2026
R is for Rootkit

In the ever-evolving world of cybersecurity, advanced threats like rootkits remain among the most dangerous. One such example is the R77 Rootkit, a highly sophisticated malware that stealthily infiltrates systems and provides backdoor access to cybercriminals. This particular rootkit has been found hosted within a seemingly innocent file: Elden Ring v1.02-v1.03 Plus 30 Trainer.exe.

In this post, we will dive deep into the R77 Rootkit, explaining how it works, how it’s distributed through popular game trainers, and how you can map and neutralize it before it causes significant damage. By using advanced mapping techniques and leveraging powerful tools, businesses can prevent the spread of this hidden threat.

The R77 Rootkit: A Stealthy Threat

The R77 Rootkit is a malicious program designed to grant attackers persistent, stealthy access to infected systems. Rootkits like R77 are particularly dangerous because they hide their presence, allowing cybercriminals to maintain control over the system without detection. Once a system is compromised, the rootkit can execute commands, manipulate files, and communicate with external servers without being noticed by traditional security measures.

This specific rootkit has been distributed in a highly unusual way, through a game trainer for the popular game Elden Ring. The file in question, Elden Ring v1.02-v1.03 Plus 30 Trainer.exe, promises to enhance the gaming experience with cheats but is actually a Trojan horse carrying the R77 Rootkit.

Mapping the R77 Rootkit: How It Works

R77 Rootkit Graph

Mapping the R77 Rootkit involves exposing the hidden behaviors and components of the malware. By analyzing the Elden Ring Trainer file with tools like PEStudio, security professionals can identify the rootkit’s malicious activities and plan appropriate countermeasures.

Here’s what we found during our analysis:

1. File Signature
The Elden Ring v1.02-v1.03 Plus 30 Trainer.exe file has been flagged as suspicious due to its file signature, which matches known patterns of rootkit infections. It has a size of 308,224 bytes and is identified as an executable.

2. PEStudio Analysis
When the Elden Ring Trainer file was analyzed using PEStudio, it revealed that the R77 Rootkit was flagged by 36 antivirus engines as malicious, indicating its high evasion capabilities.

PEStudio R77 Rootkit Virus Total

3. Malicious Imports
Several suspicious imports were discovered within the file, including:

GetCurrentProcessId: Used to track the process ID of running applications, allowing the attacker to monitor and manipulate processes.
WriteFile: A function that allows the rootkit to write data to the infected system without detection.
InternetOpenUrlA: Provides the ability to open URLs, which could be used to download additional malicious payloads or communicate with a remote server.
GetCurrentProcess: Enables the rootkit to identify and interact with other system processes, aiding in its persistence and evasion.

PEStudio R77 Rootkit Imports

4. Resource Identification
The R77 Rootkit is embedded within the Elden Ring Trainer as a remote executable resource:

PEStudio R77 Rootkit Resources

Resource Location: REMOTE, 231, executable (64-bit CPU).
Memory Range: 0x000E2E88 – 0x0012E288.
Size: 308,224 bytes.
SHA-1 Hash: 77264F8D22163C38608822D7014D6C05FC31A2BCD13E380D5AB15A0D781952D5.
Manifest Requirement: Administrator privileges.

PEStudio R77 Rootkit Manifest

This remote executable is what enables the rootkit to run persistently, without the user’s knowledge. The manifest explicitly requests administrator privileges, allowing it to gain higher-level access to the system.

Key Indicators of Compromise (IOCs) to Block

To effectively secure your environment against the R77 Rootkit, blocking the following indicators of compromise (IOCs) is critical. These IOCs represent the specific elements of the R77 Rootkit that must be addressed to prevent infection:

IOC TypeDescriptionAction
SHA-1 HashCC4864A25A305759921B73D753116873493F2C526A396839D4DA6815492299D8Block by Hash
SHA-1 Hash973e8ee15e00b702b03fa42e45cce60344dbe7dbc7d3213a81a53623c303ff5cBlock by Hash
SHA-1 Hash044d94183a778f39e47f255fcb985d20bfd885771a74217cfbca9e63d7d9936dBlock by Hash

Protecting Your System from Rootkit Threats

The R77 Rootkit, hosted within the Elden Ring v1.02-v1.03 Plus 30 Trainer.exe, is a dangerous and sophisticated threat. By distributing this rootkit through seemingly innocuous game cheats, attackers have found a way to reach an unsuspecting audience, making it an even more pervasive threat.

However, by using the right tools and techniques, such as mapping and analyzing the rootkit’s behavior and blocking critical IOCs, security teams can protect systems from infection. Proactive monitoring, coupled with a comprehensive strategy for handling rootkits, is essential to safeguard sensitive data and prevent further compromise.

At Alpha Cyber, we specialize in identifying and neutralizing advanced threats like the R77 Rootkit. If you’re ready to secure your systems and defend against hidden threats, contact us today to learn how we can help you map, detect, and block malware before it takes hold.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]