Last seven days
- First activity
- Sep 20, 2026
- Last activity
- Sep 23, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 1 hostnames
AZORult is a Windows information-stealing malware family active since at least 2016 and widely used in cybercrime operations.
Profile source: Mallory opens in a new tabAzorult
AZORult is a Windows information-stealing malware family active since at least 2016 and widely used in cybercrime operations. It is best known for harvesting data from infected systems, particularly browser-stored credentials, cookies, browsing history, cryptocurrency wallet data, and credentials stored by common applications such as Skype, Telegram, and Steam. The malware has also been observed collecting host metadata including usernames, running process lists, and time zone information, and it can capture screenshots from victim machines. Some variants can steal arbitrary files, download additional payloads, and delete files from compromised hosts.
C2 tracking
Derp observations, rolling seven-day window
Samples
0000a9cfdd51433d41e207c7fc514bc698852d96c6cade2bb4ac48dce5553a83 15956a1a62cae11be28d9e915c5cf1922a14789aa628e59b7c3dad14e771d796 57c5dfddb1c4ce5444fc8e799ef969e8b64e5c5f35669782fb5e33d94d35cb92 733c7a299177f217fe871d278a142660e63ff6c93077c20cf1de2a5aa57504b5 ef3eda5d8521bceb2f1db676cfdb5ac98a3bdf17df94040dcd8a1f5bb370a9dd 36ea38da468c43eff93b0d8a4dca458f1f575e956c8391e80f0598695d3a4567 99854a3b0132343f37d1e96973b044f973411be2663970319e69a44508260c65 9fe1bbaded9b21a23becbd130705ea02d7024f8725789fdc61b72faa5e5b4d19 b7e876e910ae0df26fd66b4e3bb0484550022e680649a35f55ed235d6f55e5d1 c54f56e5b9ab26f32d6bbacdc9dfc05be4b248a162d4847b2cc84d651e252ddb Reported operators
TA505 has used malware such as Azorult and Cobalt Strike in their operations.
The new malware includes AZORult, an information-stealing malware; the remote access tool Remcos; the DarkVNC backdoor trojan; and a clipboard cryptocurrency stealer.
Azorult is an information stealer that steals passwords from installed applications, browser cookies, cryptocurrency wallets, arbitrary files, and more. In this article, the loading phase of the Azorult stealer is analysed...
One of the samples we found was the “Azorult” stealer malware that connects to a C2 server “scat01[.]tk”.
AZORult is one of the best known malware within the Stealer family... Once the stealer is deployed... it obtains information from elements such as: Mail information, Wallets, FTP, Browsers information (Cookies, History…), SSH (Putty|WinSCP).
Unit 42 identified ten strains of info-stealers popular with SilverTerrier: AgentTesla, Atmos, AzoRult, ISpySoftware, ISR Stealer, KeyBase, LokiBot, Pony, PredatorPain, and Zeus.
The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.
In early 2017, CrydBrox offered an updated variant of the AZORult malware that included .bit support... The AZORult sample ... first checks if the C2 domain contains the string ".bit" and ... will query ... hard-coded OpenNIC IP addresses to try to resolve the domain.
Exploited software
MITRE ATT&CK
Reporting
AZORult, a long-running credential-stealing malware family tied to the Genesis Store cybercrime marketplace, has continued to appear in new delivery campaigns despite earlier reports that browser security changes had crippled its core theft capabilities. Earlier research linked more than 300,000 infections sold through Genesis to AZORult or its suppliers, showing how the malware fit into a broader malware-as-a-service and stolen-access supply chain. Although a Google Chrome update was reported to have disrupted older AZORult builds and pushed some criminal operators toward other stealers, subsequent activity indicates the malware remained in circulation through updated or repackaged campaigns. Recent and historical reporting shows AZORult being distributed through spam emails, ZIP or ISO archives, malicious LNK and HTA files, and heavily obfuscated script chains using PowerShell, batch files, JavaScript, and scheduled tasks. The malware has been used against targets including Korean users and German automotive businesses, where it stole browser credentials, cookies, autofill data, email and messaging app data, cryptocurrency wallet files, screenshots, and system information, while also supporting follow-on payload delivery. Newer campaigns emphasized in-memory execution, anti-analysis checks, and minimal disk artifacts to evade detection, underscoring AZORult's persistence as a commodity infostealer within a more outsourced and opportunistic cybercrime ecosystem.
Splunk has removed two Windows discovery analytics from its Threat Research content library and replaced them with updated detections for attacker use of built-in net commands to enumerate users and groups. The deprecated rules, Local Account Discovery with Net and Net Localgroup Discovery, identified execution of net.exe or net1.exe with arguments such as user, users, and localgroup, activity commonly used to list local accounts and group memberships on compromised hosts. The changes align with well-documented adversary behavior in MITRE ATT&CK techniques T1087.001 and T1069.001, where threat actors use commands like net user, net user /domain, and net localgroup administrators to gather account and privilege information that can support privilege escalation and lateral movement. Splunk said the removed analytics were deprecated in version 5.2.0 in favor of Windows User Discovery Via Net and Windows Group Discovery Via Net, with the original detections having relied on EDR process telemetry, Sysmon Event ID 1, Windows Security Event ID 4688, and related endpoint data sources.
MITRE ATT&CK documents local account creation as a common persistence technique under T1136.001, describing how threat groups and malware have created or enabled accounts on compromised Windows systems to maintain access and support lateral movement. Reported activity includes use of built-in commands such as net user to add accounts, sometimes followed by placement into privileged groups, with examples ranging from generic support-style usernames to attacker-controlled administrator accounts. Splunk published and later replaced a detection for this behavior that monitors endpoint process telemetry for net.exe or net1.exe creating local administrator accounts with the /add parameter and administrator-group keywords. The analytic, now superseded by Windows Create Local Administrator Account Via Net, is mapped to ATT&CK T1136.001 and is intended to help defenders spot suspicious account creation, while noting that legitimate IT administration can generate false positives.
Researchers and incident reports show the Vidar infostealer continuing to mature as a credential- and data-theft platform, with operators rotating backend infrastructure, tightening access to affiliate panels, and masking administration through Tor relays, VPN services, and hosting concentrated in Moldova and Russia. Team Cymru linked the operation to infrastructure including my-odin[.]com and several shifting IP addresses, while newer technical analysis found Vidar using multi-stage PowerShell delivery, process injection, API hooking, scheduled-task persistence, and theft of browser data by intercepting CryptProtectMemory before encryption. The malware targets Windows systems and steals credentials, cookies, autofill data, payment cards, crypto-wallet files, tokens, documents, and screenshots, then exfiltrates the data over encrypted channels. Campaigns tied to Vidar have used increasingly flexible command-and-control discovery and broad distribution channels. Analysts observed samples resolving C2 details dynamically through public profiles on Faceit, Telegram, and Steam, allowing operators to change infrastructure without rebuilding malware. Separate reporting tied Vidar to YouTube lures promoting cracked software and AI-generated tutorial videos, where victims were redirected to fake download sites that delivered stealer payloads. Earlier activity also showed Vidar deployed ahead of GandCrab ransomware, stealing victim data before downloading the encryptor, underscoring its role as both a standalone infostealer and a precursor for wider financially motivated intrusions.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.