CrydBrox is the handle associated with the original author and underground seller of the AZORult information-stealing malware, a prominent crimeware family active in the Russian-speaking cybercriminal ecosystem. AZORult was observed in use from 2016 onward and was marketed in underground forums as a modular stealer capable of harvesting browser history, login credentials, cookies, cryptocurrency wallet data, payment-card data from Chrome-based browsers, and credentials from applications such as WinSCP and Outlook. The malware also supported downloading additional payloads, indicating use beyond pure credential theft into broader post-compromise activity. CrydBrox advertised updated AZORult variants that added support for Namecoin .bit domains for command-and-control resilience and anonymity, as well as encrypted communications between the stealer and its management infrastructure. Advertised features also included anti-virtual machine, anti-sandbox, and anti-debugging protections, along with multiple build formats including executable and DLL variants compatible with other bot frameworks. AZORult has been linked to malspam delivery and use as a secondary payload alongside other malware families. A later C++ rewrite known as AZORult++ was assessed to have been developed by associates or acolytes of CrydBrox after the original author discontinued AZORult when version 3.2 became too widely available. That variant retained core AZORult communication and data-handling logic while adding the ability to enable Remote Desktop access on compromised systems by creating a hidden administrator account and modifying system settings. It also kept stolen data in memory rather than writing it to disk, reflecting an emphasis on defense evasion. The malware family includes checks to avoid execution on systems configured for several post-Soviet languages, consistent with common Russian-speaking cybercrime tradecraft. CrydBrox is best characterized as a financially motivated cybercriminal actor centered on credential theft, data theft, and malware commercialization rather than a state-directed intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.