Researchers reported the appearance of AZORult++, a C++ rewrite of the AZORult information-stealing Trojan that surfaced after sales of the original malware were reportedly halted by its main seller, CrydBrox, in late 2018. The new strain preserves several core elements of AZORult 3.3, including its command-and-control communication algorithm, command structure, harvested-data storage approach, and XOR-based encryption, indicating continuity with the earlier malware family despite the rewrite.
Analysis found the new variant to be immature and still under development, with debugging artifacts and a coding flaw that prevents its configuration string from properly controlling behavior. Even so, researchers warned it could become more dangerous than earlier versions because it can create a hidden administrator account, enable RDP, open a port, and grant attackers full remote desktop access to infected systems; the report also noted that AZORult had been widely traded on Russian-language forums and that users in Russia and India were among the most targeted at the start of 2019.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Kaspersky reported that the new C++ AZORult++ variant could enable Remote Desktop access on infected machines. The malware creates a hidden administrator account and changes the registry to allow RDP connections, making the rewrite potentially more dangerous despite its early-stage development.
In early March 2019, researchers found malicious files similar to AZORult that were written in C++ rather than Delphi. They named this rewritten malware family AZORult++.
Kaspersky statistics indicated that, since the start of 2019, users in Russia and India were the most targeted by AZORult activity. This reflects observed victim distribution at the beginning of the year.
The main AZORult seller, using the handle CrydBrox, announced that sales of AZORult were closed forever. The report places this development in late 2018 and notes it preceded the emergence of a rewritten variant.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.