AZORult is a Windows information-stealing malware family in the stealer/Trojan-PSW category that has been observed in the wild since 2016 and sold on Russian-language underground forums for about $100. It is widely recognized as a multifunctional infostealer and has been described as one of the most widespread stealer trojans, including detections on more than 25% of users who encountered Trojan-PSW malware in one cited dataset. AZORult has been used by multiple threat actors, including FIN11, TA505/GracefulSpider, GorgonGroup, and actors tracked by Unit 42 as SilverTerrier; it has also been distributed via SocGholish/FakeUpdates and was observed as a second-stage payload delivered by Chthonic in a PayPal-themed malware campaign.
High-confidence capabilities described in the content include theft of browser credentials, cookies, browsing history, web form/autofill data, payment card data, mail-related information, FTP credentials, cryptocurrency wallet data, and credentials or files from applications such as Skype, Telegram, Steam, PuTTY, and WinSCP. The malware can also collect host profiling data such as username, computer name, OS, RAM, installed software, running processes, and other system information. Specific discovery behavior mentioned includes checking the Registry key Software\Microsoft\Windows\CurrentVersion\Uninstall to enumerate installed software and collecting the username from the victim machine.
Observed infection vectors include spear-phishing documents, compromised websites, malicious downloads from websites, and loader/dropper-based delivery chains. Reported AZORult execution behavior includes use of a dropper stage, launching cmd.exe and PowerShell, dropping files into AppData\Temp, AppData\Roaming, ProgramData, and user-profile directories, checking command-and-control connectivity before continuing, and in some samples stopping execution if C2 is unavailable. Persistence and system modification behaviors mentioned in the content include scheduled task creation via schtasks /create, modification of Microsoft Office Resiliency and File MRU settings, killing winword.exe, abuse of registry changes associated with disabling notifications, and enabling Remote Assistance. The content also notes anti-analysis and anti-debugging behavior, including obfuscation, SmartAssembly-protected .NET samples, AutoIT implementations, some Nullsoft-packaged samples, some C++ samples, debug-thread and heap-flag checks, process monitoring, mutex-based reinfection avoidance in some variants, token privilege checks, thread-context abuse, and the ability to remotely suspend or shut down a device.
The content includes multiple indicators associated with AZORult samples and infrastructure. Sample SHA-256 hashes listed are 8424aa8b6fda143bd0e2e82ea906b2aee8cf49e416308cd92bd76bdcd46b866f, 38c78ebf970f2fc711eddcfa9ab6562c8ccbcfb053e5ececaa695650cf7d8727, 97710410be07f6ab12c607e9378bb399bdbe3012da245805212e2b1995065c17, fd8deb7f3c15bd91961790834864db01b5459a019777266c919465b0cac3751f, 9af44ae397fce9e4da5effb82fcecaeadc7dcb412d030c5e0e135639b3686efb, 37d4d7a7b84e4f6ead2e950ba252c23fa360a3176f49184942da3046fa693452, and c7930d104f9f1e522835dcbd6aecd707b6bdc27ec4f34149d32b90978e4a6878. Additional campaign-specific hashes mentioned include 10d159b0ddb92e9f4b395e90f9cfaa554622c4e77f66f7da176783777db5526a for an AZORult payload and detections such as Trojan:Win32/Azorult.RMA!MTB and Trojan.Win32.AZORUIT.A. Infrastructure and delivery indicators listed in the content include 91.215.154[.]202/AZORult/gate.php, bllsl2[.]shop, bllsl2[.]shop/bll/index.php, nghfh[.]com, nghfh[.]com/em/index.php, 171.22.30[.]164/standright/index.php, 85.31.45[.]29/ongod/index.php, 64.52.171[.]230/index.php, 209.208.65[.]177/index.php, 185.225.73[.]49/office/index.php, domcomp[.]info, domcomp[.]info/1210776429.php, arthurcambell.ac[.]ug/azne.exe, nanaa[.]tech/index.php, movescx[.]top, cointra[.]ac[.]ug, safetygear[.]pk, scientific[.]pk, karimgousa[.]ug, mistitis[.]ug, goldrush[.]ug, beachwood[.]ug, citypharmacylv[.]com, ddlakava[.]ac[.]ug, cracksmsa[.]ug, lastimaners[.]ug, marksidfgs[.]ug, and kenmil.ac[.]ug.
The content also references a Trend Micro-documented sample detected as Trojan.Win32.AZORUIT.A that persisted as a Windows service named localNETService, dropped %ProgramData%\localNETService\localNETService.exe and temporary .dat files, modified %Program Files%\Google\Update\GoogleUpdate.exe, created registry keys under HKLM\SOFTWARE\localNETService and HKLM\SYSTEM\ControlSet001\services\localNETService, and created scheduled tasks GoogleUpdateTaskMachineUA and GoogleUpdateTaskMachineCore masquerading as Google Update tasks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).
AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).
AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).
Unit 42 identified ten strains of info-stealers popular with SilverTerrier: AgentTesla, Atmos, AzoRult, ISpySoftware, ISR Stealer, KeyBase, LokiBot, Pony, PredatorPain, and Zeus.
The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.
In early 2017, CrydBrox offered an updated variant of the AZORult malware that included .bit support... The AZORult sample ... first checks if the C2 domain contains the string ".bit" and ... will query ... hard-coded OpenNIC IP addresses to try to resolve the domain.
39 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
Create tasks to create persistence: schtasks /create /tn /tr "<FilePath>" /sc minute /mo 1 /F
using sleeps through PS to avoid the sandbox analysis timeout or delay the execution
the most common is to see executions of this one doing the first phase launching several cmd.exe to support itself in the execution while dropping other files
By relying on basic social engineering – an attack technique that takes advantage of human traits such as curiosity, trust and greed in order to obtain confidential information or to have the victim perform a certain action – it is suffice to say that certain threat actors (both criminal and nation state) are exploiting these unprecedented times for various nefarious means.
Create tasks to create persistence: schtasks /create /tn /tr "<FilePath>" /sc minute /mo 1 /F
AZORult seen, mostly were either .NET obfuscated with SmartAssembly or AutoIT
be able to execute elements in a different thread with the context from which it has obtained all the information related to the credentials of the main process
look for permissions that it has in execution via Token to then be able to execute elements in a different thread
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Subsequently, we can see how he tries to avoid reinfection with Mutex, but not all samples used the mutex.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
it actually tries to control at several points which processes are running on the system, usually linked to anti-analysis
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
using sleeps through PS to avoid the sandbox analysis timeout or delay the execution
Examples include "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "DropBook has checked for the presence of Arabic language," and "Maze has checked the language of the infected system using the GetUSerDefaultUILanguage function."
before running most of its functions had a check where checks if it reached the C2, if this did not happen, automatically stopped the execution
In the log we can see that: A client 96.57.xx.xxx Sent a web request “GET tuneappservice.org/l3k42hj56h634gkj2lk14356jk4gh23k5jl6h4/gate.php?ped=RTY3M0E4NjhDQ0I5JE1DLTEwNw” We can see here what looks like a malware callback, it’s in fact Riltok.
The service is described as a Fast flux but in reality it’s more a simple proxy system. BraZZZers rents a pool of VPSs all around the internet and uses them as proxy IPs in order to hide the real IP of a server.
Если пользователь устанавливает такое «обновление», на устройство жертвы загружается малварь
756 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
118 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Azorult appears only in a related-content link title and is not part of the main article.
Information-stealing malware previously distributed via SocGholish.
Named malware family deployed via SocGholish.
Associated Analytic Story Azorult
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.