Last seven days
- First activity
- Aug 8, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
AZORult is a Windows information-stealing malware family that emerged in 2016 and became one of the most widely used commodity stealers in cybercrime operations.
Profile source: Mallory opens in a new tabAzorult
AZORult is a Windows information-stealing malware family that emerged in 2016 and became one of the most widely used commodity stealers in cybercrime operations. It is commonly sold on underground forums and has been used by multiple threat actors, including TA505, FIN11, and Gorgon Group. AZORult is frequently delivered through spearphishing documents, compromised websites, and fake-update style malware chains, and it has also been observed as a secondary payload delivered by other malware families and loaders such as SocGholish and Chthonic.
AZORult is designed to harvest and exfiltrate sensitive data from compromised hosts. Its collection scope includes browser credentials, cookies, browsing history, web form and autofill data, mail-related data, FTP client credentials, cryptocurrency wallet data, and information from applications such as Skype, Telegram, Steam, PuTTY, and WinSCP. It can also gather host profiling data such as the username and installed software inventory, including by querying Windows Registry locations associated with installed applications.
Operationally, AZORult commonly uses a dropper stage before the main stealer executes. Observed samples launch command shells and PowerShell during early execution, may delay activity to evade sandbox time limits, and often perform command-and-control reachability checks before proceeding. Some variants terminate if command-and-control connectivity is unavailable. Persistence has been observed through scheduled tasks and service-style mechanisms in some detections. Reported samples also show anti-analysis and anti-debugging behavior, process monitoring, mutex-based reinfection avoidance in some cases, and privilege-aware execution checks. Some variants have been described as capable of remotely suspending or shutting down a device.
Implementation and packaging have varied across campaigns, including Delphi, C++, obfuscated .NET, and AutoIT-based samples, reflecting broad criminal reuse and repackaging. AZORult has remained notable both as a standalone infostealer and as part of larger malware ecosystems that monetize stolen credentials, browser data, wallet material, and other victim information.
Samples
Reported operators
AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).
AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).
AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).
Unit 42 identified ten strains of info-stealers popular with SilverTerrier: AgentTesla, Atmos, AzoRult, ISpySoftware, ISR Stealer, KeyBase, LokiBot, Pony, PredatorPain, and Zeus.
The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.
In early 2017, CrydBrox offered an updated variant of the AZORult malware that included .bit support... The AZORult sample ... first checks if the C2 domain contains the string ".bit" and ... will query ... hard-coded OpenNIC IP addresses to try to resolve the domain.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.