Tuesday, May 6, 2025
HomeMalwareNew AZORult Malware Spreading Via Office Documents Steals to Credentials & Launch...

New AZORult Malware Spreading Via Office Documents Steals to Credentials & Launch Ransomware Attack

Published on

SIEM as a Service

Follow Us on Google News

Threat actors behind AZORult malware released an updated version with improvements on both the stealer and the downloader functionalities. Within a day after the new version released a dark web user used AZORult in a large Email campaign to distribute Hermes ransomware.

The new campaign with the updated version of AZORult delivering thousands of messages targeting North America with subjects “About a role“, “Job Application” and contains the weaponized office document “firstname.surname_resume.doc” attached.

AZORult

Attackers used password-protected documents to evade the antivirus detections and once the user enter’s the password for documents it asks to enable macros which downloads the AZORult and then the Hermes 2.1 ransomware.

- Advertisement - Google News

AZORult Advertised On Underground Forum

Security researchers from Proofpoint spotted the new version(3.2) of AZORult malware advertised in the underground forum with full changelog.

UPD v3.2
[+] Added stealing of history from browsers (except IE and Edge)
[+] Added support for cryptocurrency wallets: Exodus, Jaxx, Mist, Ethereum, Electrum, Electrum-LTC
[+] Improved loader. Now supports unlimited links. In the admin panel, you can specify the rules for how the loader works. For example: if there are cookies or saved passwords from mysite.com, then download and run the file link[.]com/soft.exe. Also, there is a rule “If there is data from cryptocurrency wallets” or “for all”
[+] Stealer can now use system proxies. If a proxy is installed on the system, but there is no connection through it, the stealer will try to connect directly (just in case)
[+] Reduced the load in the admin panel.
[+] Added to the admin panel a button for removing “dummies”, i.e. reports without useful information
[+] Added to the admin panel guest statistics
[+] Added to the admin panel a geobase

AZORult Campaign

According to researchers, the malware campaign contains both the password stealer and the ransomware, it is less common to see both. So before causing a ransomware attack, the stealer would check for cryptocurrency wallets and stolen the credentials before the files are being encrypted.

When the victims open’s the password-protected document it asks to enable macros and the macros download AZORult. Then it connects to the C&C server from the infected machine and the C&C server responds with the XOR-encoded 3-byte key.

After the initial exchange between the infected machine and the C&C server, the infected machine sends the credentials with the XOR-encoded 3-byte key. It send’s the computer information, stolen passwords, Cookies and file contents.

Then after exfiltrating stolen credentials from the infected machine, it downloads the Hermes 2.1 ransomware.

Researchers said, “the recent update to AZORult includes substantial upgrades to malware that was already well-established in both the email and web-based threat landscapes.”

Also Read

Hackers Selling HTTP Remote Access Trojan via Weaponized Word Documents in Underground Market

Dangerous Underminer Exploit Kit Delivers a Cryptocurrency-mining Malware and Bootkit

PowerGhost Malware Remotely Attack Corporate Network Servers & Workstations using EternalBlue Exploit

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Android Security Update -A Critical RCE Vulnerability Actively Exploited in the Wild 

Google has released critical security patches for Android devices to address 57 vulnerabilities across...

Hackers Exploit Fake Chrome Error Pages to Deploy Malicious Scripts on Windows Users

Hackers are leveraging a sophisticated social engineering technique dubbed "ClickFix" to trick Windows users...

New ClickFix Attack Imitates Ministry of Defence Website to Target Windows & Linux Systems

A newly identified cyberattack campaign has surfaced, leveraging the recognizable branding of India's Ministry...

Threat Actor Evades SentinelOne EDR to Deploy Babuk Ransomware

Aon’s Stroz Friedberg Incident Response Services has uncovered a method used by a threat...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Target HR Departments With Fake Resumes to Spread More_eggs Malware

The financially motivated threat group Venom Spider, also tracked as TA4557, has shifted its...

LUMMAC.V2 Stealer Uses ClickFix Technique to Deceive Users into Executing Malicious Commands

The LUMMAC.V2 infostealer malware, also known as Lumma or Lummastealer, has emerged as a...

Chimera Malware: Outsmarting Antivirus, Firewalls, and Human Defenses

X Business, a small e-commerce store dealing in handmade home décor, became the latest...