Skip to content

Azorult

AZORult is a Windows information-stealing malware family that emerged in 2016 and became one of the most widely used commodity stealers in cybercrime operations.

Profile source: Mallory opens in a new tab

Azorult

Family profile

AZORult is a Windows information-stealing malware family that emerged in 2016 and became one of the most widely used commodity stealers in cybercrime operations. It is commonly sold on underground forums and has been used by multiple threat actors, including TA505, FIN11, and Gorgon Group. AZORult is frequently delivered through spearphishing documents, compromised websites, and fake-update style malware chains, and it has also been observed as a secondary payload delivered by other malware families and loaders such as SocGholish and Chthonic.

AZORult is designed to harvest and exfiltrate sensitive data from compromised hosts. Its collection scope includes browser credentials, cookies, browsing history, web form and autofill data, mail-related data, FTP client credentials, cryptocurrency wallet data, and information from applications such as Skype, Telegram, Steam, PuTTY, and WinSCP. It can also gather host profiling data such as the username and installed software inventory, including by querying Windows Registry locations associated with installed applications.

Operationally, AZORult commonly uses a dropper stage before the main stealer executes. Observed samples launch command shells and PowerShell during early execution, may delay activity to evade sandbox time limits, and often perform command-and-control reachability checks before proceeding. Some variants terminate if command-and-control connectivity is unavailable. Persistence has been observed through scheduled tasks and service-style mechanisms in some detections. Reported samples also show anti-analysis and anti-debugging behavior, process monitoring, mutex-based reinfection avoidance in some cases, and privilege-aware execution checks. Some variants have been described as capable of remotely suspending or shutting down a device.

Implementation and packaging have varied across campaigns, including Delphi, C++, obfuscated .NET, and AutoIT-based samples, reflecting broad criminal reuse and repackaging. AZORult has remained notable both as a standalone infostealer and as part of larger malware ecosystems that monetize stolen credentials, browser data, wallet material, and other victim information.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Reconnaissance

Observed infrastructure

Last seven days

First activity
Aug 8, 2026
Last activity
Aug 8, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
TA505

AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).

FIN11

AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).

Gorgon Group

AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).

SilverTerrier

Unit 42 identified ten strains of info-stealers popular with SilverTerrier: AgentTesla, Atmos, AzoRult, ISpySoftware, ISR Stealer, KeyBase, LokiBot, Pony, PredatorPain, and Zeus.

TMT

The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.

CrydBrox

In early 2017, CrydBrox offered an updated variant of the AZORult malware that included .bit support... The AZORult sample ... first checks if the C2 domain contains the string ".bit" and ... will query ... hard-coded OpenNIC IP addresses to try to resolve the domain.

Exploited software

Vulnerabilities linked to Azorult

1 CVEs

MITRE ATT&CK

Azorult in ATT&CK

65 distinct techniques

Techniques

65 techniques
T1555 Credentials from Password Stores T1189 Drive-by Compromise T1105 Ingress Tool Transfer T1566 Phishing T1041 Exfiltration Over C2 Channel T1204 User Execution T1005 Data from Local System T1539 Steal Web Session Cookie T1012 Query Registry T1082 System Information Discovery T1059.001 PowerShell T1566.001 Spearphishing Attachment T1057 Process Discovery T1134 Access Token Manipulation T1059.003 Windows Command Shell T1112 Modify Registry T1070.004 File Deletion T1071 Application Layer Protocol T1622 Debugger Evasion T1529 System Shutdown/Reboot T1497.001 System Checks T1480.002 Mutual Exclusion T1027 Obfuscated Files or Information T1055 Process Injection T1053.005 Scheduled Task T1090.003 Multi-hop Proxy T1071.001 Web Protocols T1568 Dynamic Resolution T1568.001 Fast Flux DNS T1560 Archive Collected Data T1204.002 Malicious File T1555.003 Credentials from Web Browsers T1059.005 Visual Basic T1113 Screen Capture T1083 File and Directory Discovery T1033 System Owner/User Discovery T1588.001 Malware T1140 Deobfuscate/Decode Files or Information T1016 System Network Configuration Discovery T1614.001 System Language Discovery T1657 Financial Theft T1119 Automated Collection T1562 Impair Defenses T1566.002 Spearphishing Link T1518 Software Discovery T1048 Exfiltration Over Alternative Protocol T1584.001 Domains T1124 System Time Discovery T1573.001 Symmetric Cryptography T1090 Proxy T1583.001 Domains T1531 Account Access Removal T1562.001 Disable or Modify Tools T1489 Service Stop T1222 File and Directory Permissions Modification T1055.012 Process Hollowing T1219 Remote Access Tools T1204.001 Malicious Link T1036 Masquerading T1552.001 Credentials In Files T1021.001 Remote Desktop Protocol T1543.003 Windows Service T1548 Abuse Elevation Control Mechanism T1222.001 Windows File and Directory Permissions Modification T1134.002 Create Process with Token

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.