Skip to content

Azorult

AZORult is a Windows information-stealing malware family active since at least 2016 and widely used in cybercrime operations.

Profile source: Mallory opens in a new tab

Azorult

Family profile

AZORult is a Windows information-stealing malware family active since at least 2016 and widely used in cybercrime operations. It is best known for harvesting data from infected systems, particularly browser-stored credentials, cookies, browsing history, cryptocurrency wallet data, and credentials stored by common applications such as Skype, Telegram, and Steam. The malware has also been observed collecting host metadata including usernames, running process lists, and time zone information, and it can capture screenshots from victim machines. Some variants can steal arbitrary files, download additional payloads, and delete files from compromised hosts.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Process Injection
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 20, 2026
Last activity
Sep 23, 2026
Feed role
C2 / Distribution
Host form
1 IP / 1 hostnames

Leading locations

  • IR1
  • US1

Leading providers

  • Amazon.com, Inc.1
  • Iran Telecommunication Company PJS1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

8 named in public reporting
TA505

TA505 has used malware such as Azorult and Cobalt Strike in their operations.

Tor2Mine

The new malware includes AZORult, an information-stealing malware; the remote access tool Remcos; the DarkVNC backdoor trojan; and a clipboard cryptocurrency stealer.

Gorgon Group

Azorult is an information stealer that steals passwords from installed applications, browser cookies, cryptocurrency wallets, arbitrary files, and more. In this article, the loading phase of the Azorult stealer is analysed...

scat01

One of the samples we found was the “Azorult” stealer malware that connects to a C2 server “scat01[.]tk”.

FIN11

AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).

SilverTerrier

Unit 42 identified ten strains of info-stealers popular with SilverTerrier: AgentTesla, Atmos, AzoRult, ISpySoftware, ISR Stealer, KeyBase, LokiBot, Pony, PredatorPain, and Zeus.

TMT

The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.

CrydBrox

In early 2017, CrydBrox offered an updated variant of the AZORult malware that included .bit support... The AZORult sample ... first checks if the C2 domain contains the string ".bit" and ... will query ... hard-coded OpenNIC IP addresses to try to resolve the domain.

Exploited software

Vulnerabilities linked to Azorult

2 CVEs

MITRE ATT&CK

Azorult in ATT&CK

104 distinct techniques

Techniques

104 techniques
T1059.005 Visual Basic T1555 Credentials from Password Stores T1021.001 Remote Desktop Protocol T1112 Modify Registry T1136 Create Account T1005 Data from Local System T1566 Phishing T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1592 Gather Victim Host Information T1589 Gather Victim Identity Information T1056.004 Credential API Hooking T1056 Input Capture T1555.003 Credentials from Web Browsers T1588.001 Malware T1113 Screen Capture T1057 Process Discovery T1140 Deobfuscate/Decode Files or Information T1614.001 System Language Discovery T1082 System Information Discovery T1070.004 File Deletion T1016 System Network Configuration Discovery T1001 Data Obfuscation T1033 System Owner/User Discovery T1083 File and Directory Discovery T1573 Encrypted Channel T1203 Exploitation for Client Execution T1124 System Time Discovery T1055.012 Process Hollowing T1189 Drive-by Compromise T1027 Obfuscated Files or Information T1204 User Execution T1041 Exfiltration Over C2 Channel T1566.001 Spearphishing Attachment T1027.015 Compression T1056.001 Keylogging T1190 Exploit Public-Facing Application T1649 Steal or Forge Authentication Certificates T1218.005 Mshta T1204.002 Malicious File T1055 Process Injection T1218.003 CMSTP T1217 Browser Information Discovery T1027.003 Steganography T1106 Native API T1059.007 JavaScript T1059.001 PowerShell T1562.001 Disable or Modify Tools T1070 Indicator Removal T1562 Impair Defenses T1048 Exfiltration Over Alternative Protocol T1583 Acquire Infrastructure T1053.005 Scheduled Task T1539 Steal Web Session Cookie T1012 Query Registry T1620 Reflective Code Loading T1036 Masquerading T1547.001 Registry Run Keys / Startup Folder T1564.003 Hidden Window T1548.002 Bypass User Account Control T1566.002 Spearphishing Link T1059 Command and Scripting Interpreter T1560 Archive Collected Data T1129 Shared Modules T1497.001 System Checks T1497 Virtualization/Sandbox Evasion T1567 Exfiltration Over Web Service T1078 Valid Accounts T1573.001 Symmetric Cryptography T1552.001 Credentials In Files T1059.003 Windows Command Shell T1497.003 Time Based Checks T1036.005 Match Legitimate Resource Name or Location T1027.002 Software Packing T1134.002 Create Process with Token T1071.001 Web Protocols T1213 Data from Information Repositories T1011 Exfiltration Over Other Network Medium T1132 Data Encoding T1518 Software Discovery T1555.001 Keychain T1136.001 Local Account T1069.001 Local Groups T1543 Create or Modify System Process T1134 Access Token Manipulation T1622 Debugger Evasion T1529 System Shutdown/Reboot T1480.002 Mutual Exclusion T1090.003 Multi-hop Proxy T1568 Dynamic Resolution T1568.001 Fast Flux DNS T1657 Financial Theft T1119 Automated Collection T1584.001 Domains T1090 Proxy T1583.001 Domains T1531 Account Access Removal T1489 Service Stop T1222 File and Directory Permissions Modification T1219 Remote Access Tools T1204.001 Malicious Link T1543.003 Windows Service T1548 Abuse Elevation Control Mechanism T1222.001 Windows File and Directory Permissions Modification

Reporting

Research mentioning Azorult

Aug 12
Cylance Threatvector

Blog | Arctic Wolf

AZORult, a long-running credential-stealing malware family tied to the Genesis Store cybercrime marketplace, has continued to appear in new delivery campaigns despite earlier reports that browser security changes had crippled its core theft capabilities. Earlier research linked more than 300,000 infections sold through Genesis to AZORult or its suppliers, showing how the malware fit into a broader malware-as-a-service and stolen-access supply chain. Although a Google Chrome update was reported to have disrupted older AZORult builds and pushed some criminal operators toward other stealers, subsequent activity indicates the malware remained in circulation through updated or repackaged campaigns. Recent and historical reporting shows AZORult being distributed through spam emails, ZIP or ISO archives, malicious LNK and HTA files, and heavily obfuscated script chains using PowerShell, batch files, JavaScript, and scheduled tasks. The malware has been used against targets including Korean users and German automotive businesses, where it stole browser credentials, cookies, autofill data, email and messaging app data, cryptocurrency wallet files, screenshots, and system information, while also supporting follow-on payload delivery. Newer campaigns emphasized in-memory execution, anti-analysis checks, and minimal disk artifacts to evade detection, underscoring AZORult's persistence as a commodity infostealer within a more outsourced and opportunistic cybercrime ecosystem.

May 13
Splunk Research

Detection: Net Localgroup Discovery | Splunk Security Content

Splunk has removed two Windows discovery analytics from its Threat Research content library and replaced them with updated detections for attacker use of built-in net commands to enumerate users and groups. The deprecated rules, Local Account Discovery with Net and Net Localgroup Discovery, identified execution of net.exe or net1.exe with arguments such as user, users, and localgroup, activity commonly used to list local accounts and group memberships on compromised hosts. The changes align with well-documented adversary behavior in MITRE ATT&CK techniques T1087.001 and T1069.001, where threat actors use commands like net user, net user /domain, and net localgroup administrators to gather account and privilege information that can support privilege escalation and lateral movement. Splunk said the removed analytics were deprecated in version 5.2.0 in favor of Windows User Discovery Via Net and Windows Group Discovery Via Net, with the original detections having relied on EDR process telemetry, Sysmon Event ID 1, Windows Security Event ID 4688, and related endpoint data sources.

May 13
Splunk Research

Detection: Local Account Discovery with Net | Splunk Security Content

May 13
Splunk Research

Detection: Create local admin accounts using net exe | Splunk Security Content

MITRE ATT&CK documents local account creation as a common persistence technique under T1136.001, describing how threat groups and malware have created or enabled accounts on compromised Windows systems to maintain access and support lateral movement. Reported activity includes use of built-in commands such as net user to add accounts, sometimes followed by placement into privileged groups, with examples ranging from generic support-style usernames to attacker-controlled administrator accounts. Splunk published and later replaced a detection for this behavior that monitors endpoint process telemetry for net.exe or net1.exe creating local administrator accounts with the /add parameter and administrator-group keywords. The analytic, now superseded by Windows Create Local Administrator Account Via Net, is mapped to ATT&CK T1136.001 and is intended to help defenders spot suspicious account creation, while noting that legitimate IT administration can generate false positives.

May 7
Malpedia

Vidar (Malware Family)

Researchers and incident reports show the Vidar infostealer continuing to mature as a credential- and data-theft platform, with operators rotating backend infrastructure, tightening access to affiliate panels, and masking administration through Tor relays, VPN services, and hosting concentrated in Moldova and Russia. Team Cymru linked the operation to infrastructure including my-odin[.]com and several shifting IP addresses, while newer technical analysis found Vidar using multi-stage PowerShell delivery, process injection, API hooking, scheduled-task persistence, and theft of browser data by intercepting CryptProtectMemory before encryption. The malware targets Windows systems and steals credentials, cookies, autofill data, payment cards, crypto-wallet files, tokens, documents, and screenshots, then exfiltrates the data over encrypted channels. Campaigns tied to Vidar have used increasingly flexible command-and-control discovery and broad distribution channels. Analysts observed samples resolving C2 details dynamically through public profiles on Faceit, Telegram, and Steam, allowing operators to change infrastructure without rebuilding malware. Separate reporting tied Vidar to YouTube lures promoting cracked software and AI-generated tutorial videos, where victims were redirected to fake download sites that delivered stealer payloads. Earlier activity also showed Vidar deployed ahead of GandCrab ransomware, stealing victim data before downloading the encryptor, underscoring its role as both a standalone infostealer and a precursor for wider financially motivated intrusions.

Aug 28
Aryaka

Vidar Infostealer in Action From API Hooking to Covert Data Exfiltration

Aug 25
Gatewatcher

Utilisation de faux profils Steam : Vidar Stealer prend les commandes - Gatewatcher

Jan 12
Cyble

Sneaky Azorult Back In Action And Goes Undetected - Cyble

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.