AZORult is a commodity information-stealing malware family targeting Windows systems, first observed in 2016. It steals browser-stored credentials, cookies, browsing history, cryptocurrency wallet files, and other files, as well as credentials stored by applications such as Skype, Telegram, and Steam. It can capture screenshots and gather extensive host information, including running processes, installed software, operating system and hardware details, usernames, network configuration, language settings, and time zones.
AZORult can download and execute additional malware and has delivered Hermes ransomware. Its execution and evasion techniques include process hollowing, in-memory payload decryption, file deletion, XOR-based content and command-and-control encryption, and Base64 decoding of command-and-control configuration. It also supports creating processes with local SYSTEM privileges through access-token manipulation.
AZORult has been distributed through malicious spam and phishing campaigns and as a secondary payload delivered by Chthonic and Emotet. Multiple cybercriminal actors use the family, including TA505. It has appeared in campaigns targeting industrial organizations, and stolen data from AZORult infections has supplied the Genesis Store cybercrime marketplace.
AZORult++, a C++ variant observed in March 2019, adds remote access through RDP by creating a hidden administrator account and enabling Remote Desktop access. It retains stolen data in memory to reduce disk artifacts and terminates execution on systems configured with certain regional languages. This variant has less extensive browser-stealing functionality than AZORult 3.3 and lacks that version's additional-payload loading capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The malicious spam messages were crafted to exploit CVE-2017-11882. The remote code execution flaw is specific to Microsoft Word Equation Editor. Once exploited, the Warzone RAT payload is downloaded and installed. | We have observed the following families tied to the malware-based campaigns: Lokibot Agent Tesla AZORult Adwind
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA505 has used malware such as Azorult and Cobalt Strike in their operations.
The new malware includes AZORult, an information-stealing malware; the remote access tool Remcos; the DarkVNC backdoor trojan; and a clipboard cryptocurrency stealer.
Azorult is an information stealer that steals passwords from installed applications, browser cookies, cryptocurrency wallets, arbitrary files, and more. In this article, the loading phase of the Azorult stealer is analysed...
One of the samples we found was the “Azorult” stealer malware that connects to a C2 server “scat01[.]tk”.
AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).
Unit 42 identified ten strains of info-stealers popular with SilverTerrier: AgentTesla, Atmos, AzoRult, ISpySoftware, ISR Stealer, KeyBase, LokiBot, Pony, PredatorPain, and Zeus.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Azorult can decrypt the payload into memory, create a new suspended process of itself, then inject a decrypted payload to the new process and resume new process execution.
Azorult can steal credentials in files belonging to common software such as Skype, Telegram, and Steam.
Azorult can check for installed software on the system under the Registry key Software\Microsoft\Windows\CurrentVersion\Uninstall.
Azorult can collect host IP information from the victim’s machine.
Azorult can collect the username from the victim’s machine.
Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot.
Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language.
1,253 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing trojan focused on capturing passwords and financial/personal information; mentioned here as an initial misidentification of the sample.
Information-stealing trojan used in COVID-themed phishing campaigns; also targeted shipping and logistics in early 2020.
Azorult appears only in a related-content link title and is not part of the main article.
Info-stealer Campaign targets German Car Dealerships and Manufacturers Azorult BitRAT Raccoon
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.