AZORult, a long-running credential-stealing malware family tied to the Genesis Store cybercrime marketplace, has continued to appear in new delivery campaigns despite earlier reports that browser security changes had crippled its core theft capabilities. Earlier research linked more than 300,000 infections sold through Genesis to AZORult or its suppliers, showing how the malware fit into a broader malware-as-a-service and stolen-access supply chain. Although a Google Chrome update was reported to have disrupted older AZORult builds and pushed some criminal operators toward other stealers, subsequent activity indicates the malware remained in circulation through updated or repackaged campaigns.
Recent and historical reporting shows AZORult being distributed through spam emails, ZIP or ISO archives, malicious LNK and HTA files, and heavily obfuscated script chains using PowerShell, batch files, JavaScript, and scheduled tasks. The malware has been used against targets including Korean users and German automotive businesses, where it stole browser credentials, cookies, autofill data, email and messaging app data, cryptocurrency wallet files, screenshots, and system information, while also supporting follow-on payload delivery. Newer campaigns emphasized in-memory execution, anti-analysis checks, and minimal disk artifacts to evade detection, underscoring AZORult's persistence as a commodity infostealer within a more outsourced and opportunistic cybercrime ecosystem.

Pull IOCs and campaign context straight into your stack.
15 events from the most recent confirmed update back to the earliest known activity.
Kaspersky reported that Babuk ransomware source code was released in September 2021. The release was cited as part of a broader trend of leaked offensive tooling lowering barriers for cybercriminals.
A phishing and malware campaign targeting German automotive organizations was active by the end of July 2021. The operation used German-language phishing emails, ISO attachments, and HTA-based infection chains to deliver commodity stealers including AZORult.
A March 2021 analysis detailed a multistage AZORult infection chain starting from a malicious Excel workbook and using VBA, JavaScript, VBScript, PowerShell, .NET components, and LOLBins such as mshta, schtasks, and cmstp. The article linked the sample to Gorgon Group cluster one and documented persistence via Run keys and scheduled tasks, a CMSTP-based UAC bypass, Defender tampering, and process hollowing into svchost.exe.
A new 32 GUID class appeared on the Genesis market in late 2019. It did not replace the dominant 8-8-8-8-8 class.
AZORult's original developer stopped sales and maintenance in late 2018 after the malware's source code became widespread and spawned offshoots. Despite this, the malware remained active in later campaigns.
In late 2018, Genesis Store shifted from its earlier GUID class to the 8-8-8-8-8 GUID pattern and increased the number of infected machines it offered. Researchers later tied this dominant class to AZORult.
By 2018, Russian-speaking cybercriminals had concluded that targeting organizations was more profitable than targeting individual users or Russian banks. Kaspersky says this shift helped drive greater use of ransomware, stealers, and purchased access.
Genesis Store began operating in 2018 as a pay-per-bot cybercrime marketplace selling data from infected machines. During its first year, it initially sold infections in the {MACHINENAME}_20 GUID class.
AZORult was first identified as an information-stealing malware family in 2016. It was designed to steal browser data, credentials, and cryptocurrency-related information, and could also download additional malware.
Cyble analyzed an AZORult campaign using ZIP archives with malicious LNK files disguised as PDFs, followed by obfuscated PowerShell, JavaScript, scheduled tasks, and an in-memory loader. The final payload stole browser data, credentials, wallet files, application data, screenshots, and system information before exfiltration.
The German automotive-focused campaign sent major phishing waves at the end of October 2021, the end of November 2021, and in mid-March 2022. Researchers linked the operation to more than 30 lookalike domains and infrastructure including bornagroup[.]ir.
ASEC discovered an AZORult campaign distributed through spam email attachments, including a lure archive named "Estimate Request_Construction Floor Plan.7z," indicating Korean users were among the targets. The malware stole extensive browser, email, wallet, messaging, and system data and could also download additional payloads.
Genesis Store recently abandoned AZORult as its dominant infection type and shifted to a currently unidentified trojan. The change was presented as evidence that Genesis maintained relationships with multiple malware providers.
Since mid-February, multiple cybercrime forum discussions claimed a recent Google Chrome update broke AZORult's main browser-password theft capability by changing how saved passwords were protected. Forum participants described the malware as effectively decommissioned.
Using scraped Genesis data and official AZORult logs from a malware-as-a-service provider, researchers confirmed that Genesis Store's dominant 8-8-8-8-8 GUID class was AZORult-based. They linked more than 300,000 Genesis infections to AZORult or AZORult-derived suppliers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 130 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
threatvector.cylance.com
Open sourcecyble.com
Open sourceblog.checkpoint.com
Open sourcesecurelist.com
Open sourcemaxkersten.nl
Open sourceasec.ahnlab.com
Open sourceke-la.com
Open sourceke-la.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.