Netskope Threat Labs

Azorult

ATP Sandbox Adv. HeuristicsAV

Azorult (a.k.a. PuffStealer) is an information stealer sold on underground forums that harvests saved passwords, browser cookies, cryptocurrency wallets, and other sensitive data from infected systems. It first appeared around 2016, and its leaked source code has enabled cyberattackers to produce numerous modified variants. Distributors commonly bundle it with fake software installers, cracked applications, and loaders sold through malware as a service marketplaces.

First seen
January 2022
Last seen
October 2026
AZORult

16 techniques across 5 tactics.

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1012Query Registry
  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1124System Time Discovery

TA0009 Collection

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Infostealer.Azorult
ByteCode-MSIL.Trojan.Azorult
ByteCode-MSIL.Trojan.AZORult
Gen:Variant.Babar.Azorult.51654
Gen:Variant.Bulz.Azorult.348732
Gen:Variant.Fragtor.Azorult.68839
Gen:Variant.Johnnie.Azorult.110305
Gen:Variant.Razy.Azorult.916884
Gen:Variant.Ser.Ursu.Azorult.3584
Gen:Variant.Terkcop.Azorult.16