Jaxx is a cybercriminal actor associated with the sale of Azury, a C# infostealer marketed as a semi-FUD credential and data theft tool. The actor has advertised the complete source code package together with a dedicated operator panel, indicating involvement in malware development or malware commercialization rather than only operational deployment. Azury is positioned as a broad-spectrum infostealer designed to harvest browser-stored data, credentials, cookies, cryptocurrency wallet data, exchange logins, messaging-platform tokens and session data, VPN credentials, password-manager data, gaming-account data, and system and remote-access credentials. Capabilities associated with the malware sold by Jaxx include credential theft, session theft, keylogging, clipboard monitoring, arbitrary file collection, persistence, and exfiltration. The malware is also advertised with anti-analysis and defense-evasion features including anti-debugging, anti-virtual-machine, and anti-sandbox protections. Stolen information is packaged in memory and exfiltrated through operator-configurable channels. The available information supports classifying Jaxx as a financially motivated malware seller operating in the infostealer ecosystem. No high-confidence attribution to a nation state, specific country of origin, or specific victim geography is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.