Azorult

MITRE ATT&CK: S0344 View on attack.mitre.org

Aliases: PuffStealer, Rultazo, Azorult

First seen
2016-01-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
6462 (4030 malicious)
Last IoC activity
2026-09-02 03:13:48
Profile updated
2026-07-07 12:54:44

Targeted industries: financial-services retail-and-hospitality

Targeted regions: country_code:us

Context

Azorult is a commercial Trojan that is used to steal information from compromised hosts. Azorult has been observed in the wild as early as 2016. In July 2018, Azorult was seen used in a spearphishing campaign against targets in North America. Azorult has been seen used for cryptocurrency theft.

Recent IoC activity

4,031 malicious indicators in Maltiverse are attributed to Azorult (S0344). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname cryptotrust.today.md-35.webhostbox.net 2026-09-03 2
hostname abscete.info 2026-09-03 3
hostname sskyokker256.bit.md-89.webhostbox.net 2026-09-03 2
hostname a0422199.xsph.ru 2026-09-03 3
hostname a0392617.xsph.ru 2026-09-03 2
hostname f0412066.xsph.ru 2026-09-03 2
hostname aimnawnt.beget.tech 2026-09-03 3
hostname f0425296.xsph.ru 2026-09-03 3
hostname f0406552.xsph.ru 2026-09-03 2
hostname f0396130.xsph.ru 2026-09-03 2
hostname erxst.info 2026-09-03 3
hostname doc-0c-8c-docs.googleusercontent.com 2026-09-03 4
hostname a0450603.xsph.ru 2026-09-03 2
hostname cbmagency.com 2026-09-03 4
hostname ccilfov.ro 2026-09-03 4
hostname ciuj.ir 2026-09-03 4
hostname f0420740.xsph.ru 2026-09-03 2
hostname a0455475.xsph.ru 2026-09-03 2
hostname mosoli.com 2026-09-03 4
hostname f0409474.xsph.ru 2026-09-03 2

Detection coverage

  • 2 YARA rules
  • 252 Sigma rules

Malware & tools used

  • File Deletion (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Query Registry (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Time Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Process Discovery (attack-pattern)
  • Create Process with Token (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Azorult_Auto (yara-rule)
  • CAPE_Azorult (yara-rule)

Reports & references

  • telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
  • medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
  • medium.com — Operation Synctrek E5013Df8D167 (report)
  • go.recordedfuture.com — Cta 2022 0802 (report)
  • yoroi.company — Aggah How To Run A Botnet Without Renting A Server For More Than A Year (report)
  • spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
  • marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
  • proofpoint.com — New Whiteshadow Downloader Uses Microsoft Sql Retrieve Malware (report)
  • ciphertechsolutions.com — Roboski Global Recovery Automation (report)
  • securityintelligence.com — Roboski Global Recovery Automation (report)
  • cocomelonc.github.io — Simple Malware Av Evasion (report)
  • community.riskiq.com — 56E28880 (report)
  • research.checkpoint.com — Following The Scent Of Trickgate 6 Year Old Packer Used To Deploy The Most Wanted Malware (report)
  • cybereason.com — The Hole In The Bucket Attackers Abuse Bitbucket To Deliver An Arsenal Of Malware (report)
  • blueliv.com — Using Qiling Framework To Unpack Ta505 Packed Samples (report)
  • outpost24.com — Using Qiling Framework To Unpack Ta505 Packed Samples (report)
  • ke-la.com — Information Stealers A New Landscape (report)
  • Trend Micro — Campaign Abusing Rats Uses Fake Websites (report)
  • bleepingcomputer.com — Azorult Trojan Serving Aurora Ransomware By Malactor Oktropys (report)
  • resources.malwarebytes.com — Ctnt Q1 2020 Covid Report Final (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Azorult (report)
  • proofpoint.com — Threat Actors Using Legitimate Paypal Accounts To Distribute Chthonic Banking Trojan (report)
  • Cisco Talos — Tor2Mine Is Up To Their Old Tricks And 11 (report)
  • fr3d.hk — Gazorp Thieving From Thieves (report)
  • any.run — Azorult Malware Analysis (report)

External references