Azorult

S0344

Malware.View on attack.mitre.org

About this malware

Azorult is a commercial Trojan that is used to steal information from compromised hosts. Azorult has been observed in the wild as early as 2016.
In July 2018, Azorult was seen used in a spearphishing campaign against targets in North America. Azorult has been seen used for cryptocurrency theft.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1012
Query Registry

Azorult can check for installed software on the system under the Registry key Software\Microsoft\Windows\CurrentVersion\Uninstall.

T1016
System Network Configuration Discovery

Azorult can collect host IP information from the victim’s machine.

T1033
System Owner/User Discovery

Azorult can collect the username from the victim’s machine.

T1055.012
Process Hollowing

Azorult can decrypt the payload into memory, create a new suspended process of itself, then inject a decrypted payload to the new process and resume new process execution.

T1057
Process Discovery

Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot.

T1070.004
File Deletion

Azorult can delete files from victim machines.

T1082
System Information Discovery

Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language.

T1083
File and Directory Discovery

Azorult can recursively search for files in folders and collects files from the desktop with certain extensions.

T1105
Ingress Tool Transfer

Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes.

T1113
Screen Capture

Azorult can capture screenshots of the victim’s machines.

T1124
System Time Discovery

Azorult can collect the time zone information from the system.

T1134.002
Create Process with Token

Azorult can call WTSQueryUserToken and CreateProcessAsUser to start a new process with local system privileges.

T1140
Deobfuscate/Decode Files or Information

Azorult uses an XOR key to decrypt content and uses Base64 to decode the C2 address.

T1552.001
Credentials In Files

Azorult can steal credentials in files belonging to common software such as Skype, Telegram, and Steam.

T1555.003
Credentials from Web Browsers

Azorult can steal credentials from the victim's browser.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Proofpoint Azorult July 2018 Open source
    Proofpoint. (2018, July 30). New version of AZORult stealer improves loading features, spreads alongside ransomware in new campaign. Retrieved November 29, 2018.
  2. Unit42 Azorult Nov 2018 Open source
    Yan, T., et al. (2018, November 21). New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit. Retrieved November 29, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.