Description
Azorult (a.k.a. PuffStealer) is an information stealer sold on underground forums that harvests saved passwords, browser cookies, cryptocurrency wallets, and other sensitive data from infected systems. It first appeared around 2016, and its leaked source code has enabled cyberattackers to produce numerous modified variants. Distributors commonly bundle it with fake software installers, cracked applications, and loaders sold through malware as a service marketplaces.
Stats
- First seen
- January 2022
- Last seen
- October 2026
Also known as
AZORult
MITRE ATT&CK techniques
16 techniques across 5 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Infostealer.Azorult |
| ByteCode-MSIL.Trojan.Azorult |
| ByteCode-MSIL.Trojan.AZORult |
| Gen:Variant.Babar.Azorult.51654 |
| Gen:Variant.Bulz.Azorult.348732 |
| Gen:Variant.Fragtor.Azorult.68839 |
| Gen:Variant.Johnnie.Azorult.110305 |
| Gen:Variant.Razy.Azorult.916884 |
| Gen:Variant.Ser.Ursu.Azorult.3584 |
| Gen:Variant.Terkcop.Azorult.16 |



