Researchers reported that Azov was not a conventional ransomware operation but a destructive polymorphic wiper designed to cause severe and often unrecoverable damage on Windows systems. The malware spread through the SmokeLoader botnet and trojanized software, then infected suitable 64-bit PE executables by injecting re-encrypted shellcode and appending encoded resources. Once active, Azov intermittently corrupted files by overwriting 666-byte blocks with random data and adding the .azov extension, while also maintaining persistence, using anti-analysis techniques, and relying on a time-based logic bomb.
Analysis found no evidence of network communications or data exfiltration, reinforcing the conclusion that Azov’s purpose was destruction rather than extortion. Check Point identified two closely related Azov variants and noted that more than 17,000 Azov-related samples had appeared on VirusTotal by late 2022, suggesting broad and indiscriminate propagation that obscured any original targeting. The malware was manually written in assembly with FASM and used a custom shellcode decryption routine, while its distribution through the SmokeLoader malware family helped amplify infections at scale.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Check Point Research reported that by November 2022 it had observed more than 17,000 Azov-related samples submitted to VirusTotal. The volume reflected widespread distribution that obscured any original targeting.
The analyzed newer Azov sample contained a time-based logic bomb set to begin its destructive routine at 10:14:30 AM UTC on October 27, 2022. After that trigger time, it traversed directories, intermittently overwrote file contents, and appended the .azov extension to wiped files.
Check Point Research published a technical report concluding that Azov was not conventional ransomware but an advanced polymorphic wiper. The report said Azov spread via SmokeLoader and trojanized software, backdoored 64-bit executables, and showed no network activity or data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.