Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
It also implements a variety of anti-analysis techniques: Opaque predicates Anti-debug Syntactic bloat and junk code Using CALL instructions instead of RET or JMP Dynamically creating the Import Address Table
It also implements polymorphic code creation to inject itself into legitimate EXE files on the infected machine.
The wiping procedure uses a trigger time – there is a loop where the analyzed sample checks system time, and if it is not equal to or larger than the trigger time, it sleeps 10s and loops again.
Azov creates persistence by trojanizing the 64-bit Windows system binary msiexec.exe or perfmon.exe and saving it as rdpclient.exe. A registry entry at SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run is created pointing to the newly created file.
Preventing usage of software breakpoints – using routines that copy already decrypted and currently executing parts of shellcode to newly allocated memory and later transferring execution to it will sooner or later result in an exception if software breakpoints are set.
The wiping procedure uses a trigger time – there is a loop where the analyzed sample checks system time, and if it is not equal to or larger than the trigger time, it sleeps 10s and loops again.
Preventing usage of software breakpoints – using routines that copy already decrypted and currently executing parts of shellcode to newly allocated memory and later transferring execution to it will sooner or later result in an exception if software breakpoints are set.
The sudden spike in wiper malware began early in the year with numerous new wiper samples targeted at Ukraine. It displayed a side of cyberattacks we rarely see: pure destruction.
The DoubleZero wiper, for instance, only erases the first 4096 bytes of targeted files... The Azov wiper also implemented a somewhat more optimized wiping process. It does not remove all data in each file. Instead, it only targets 666 bytes in an alternating pattern...
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sophisticated assembly-written wiper with polymorphic code creation, persistence via backdooring legitimate EXE files, anti-analysis features, and an optimized wiping pattern overwriting alternating 666-byte blocks.
Azov is a destructive ransomware/wiper that intermittently overwrites file contents with random data, appends the .azov extension in newer variants, creates persistence by trojanizing 64-bit Windows binaries, and polymorphically backdoors 64-bit .exe files across the compromised system. The report emphasizes that it behaves more like a data wiper/virus than conventional ransomware, uses assembly-written and obfuscated code, includes anti-analysis techniques, and spreads via SmokeLoader and trojanized programs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.