Azorult
MITRE ATT&CK: S0344 View on attack.mitre.org
Aliases: PuffStealer, Rultazo, Azorult
- First seen
- 2016-01-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 6462 (4030 malicious)
- Last IoC activity
- 2026-09-02 03:13:48
- Profile updated
- 2026-07-07 12:54:44
Targeted industries: financial-services retail-and-hospitality
Targeted regions: country_code:us
Context
Azorult is a commercial Trojan that is used to steal information from compromised hosts. Azorult has been observed in the wild as early as 2016. In July 2018, Azorult was seen used in a spearphishing campaign against targets in North America. Azorult has been seen used for cryptocurrency theft.
Recent IoC activity
4,031 malicious indicators in Maltiverse are attributed to Azorult (S0344). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | cryptotrust.today.md-35.webhostbox.net | 2026-09-03 | 2 |
| hostname | abscete.info | 2026-09-03 | 3 |
| hostname | sskyokker256.bit.md-89.webhostbox.net | 2026-09-03 | 2 |
| hostname | a0422199.xsph.ru | 2026-09-03 | 3 |
| hostname | a0392617.xsph.ru | 2026-09-03 | 2 |
| hostname | f0412066.xsph.ru | 2026-09-03 | 2 |
| hostname | aimnawnt.beget.tech | 2026-09-03 | 3 |
| hostname | f0425296.xsph.ru | 2026-09-03 | 3 |
| hostname | f0406552.xsph.ru | 2026-09-03 | 2 |
| hostname | f0396130.xsph.ru | 2026-09-03 | 2 |
| hostname | erxst.info | 2026-09-03 | 3 |
| hostname | doc-0c-8c-docs.googleusercontent.com | 2026-09-03 | 4 |
| hostname | a0450603.xsph.ru | 2026-09-03 | 2 |
| hostname | cbmagency.com | 2026-09-03 | 4 |
| hostname | ccilfov.ro | 2026-09-03 | 4 |
| hostname | ciuj.ir | 2026-09-03 | 4 |
| hostname | f0420740.xsph.ru | 2026-09-03 | 2 |
| hostname | a0455475.xsph.ru | 2026-09-03 | 2 |
| hostname | mosoli.com | 2026-09-03 | 4 |
| hostname | f0409474.xsph.ru | 2026-09-03 | 2 |
Detection coverage
- 2 YARA rules
- 252 Sigma rules
Malware & tools used
- File Deletion (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Process Hollowing (attack-pattern)
- Query Registry (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Credentials In Files (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Time Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Process Discovery (attack-pattern)
- Create Process with Token (attack-pattern)
Used by threat actors
- TA505 (threat-actor)
Detection rules
- MALPEDIA_Win_Azorult_Auto (yara-rule)
- CAPE_Azorult (yara-rule)
Reports & references
- telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
- medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
- medium.com — Operation Synctrek E5013Df8D167 (report)
- go.recordedfuture.com — Cta 2022 0802 (report)
- yoroi.company — Aggah How To Run A Botnet Without Renting A Server For More Than A Year (report)
- spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
- marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
- proofpoint.com — New Whiteshadow Downloader Uses Microsoft Sql Retrieve Malware (report)
- ciphertechsolutions.com — Roboski Global Recovery Automation (report)
- securityintelligence.com — Roboski Global Recovery Automation (report)
- cocomelonc.github.io — Simple Malware Av Evasion (report)
- community.riskiq.com — 56E28880 (report)
- research.checkpoint.com — Following The Scent Of Trickgate 6 Year Old Packer Used To Deploy The Most Wanted Malware (report)
- cybereason.com — The Hole In The Bucket Attackers Abuse Bitbucket To Deliver An Arsenal Of Malware (report)
- blueliv.com — Using Qiling Framework To Unpack Ta505 Packed Samples (report)
- outpost24.com — Using Qiling Framework To Unpack Ta505 Packed Samples (report)
- ke-la.com — Information Stealers A New Landscape (report)
- Trend Micro — Campaign Abusing Rats Uses Fake Websites (report)
- bleepingcomputer.com — Azorult Trojan Serving Aurora Ransomware By Malactor Oktropys (report)
- resources.malwarebytes.com — Ctnt Q1 2020 Covid Report Final (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Azorult (report)
- proofpoint.com — Threat Actors Using Legitimate Paypal Accounts To Distribute Chthonic Banking Trojan (report)
- Cisco Talos — Tor2Mine Is Up To Their Old Tricks And 11 (report)
- fr3d.hk — Gazorp Thieving From Thieves (report)
- any.run — Azorult Malware Analysis (report)