April 6, 2020 By David Bisson 2 min read

Security researchers spotted a multi-pronged attack campaign that delivered a variant of the AZORult family along with other malicious payloads.

Cisco Talos learned of the AZORult-toting campaign after a telemetry entry revealed a process that involved the execution of a PowerShell loader. Upon closer examination, researchers determined that the PowerShell process came from an executable dropper contained within an ISO image. The attack instance observed by Cisco Talos downloaded a compressed version of the ISO image with ZIP onto the victim’s machine, a technique that indicates the attack likely originated from an email.

Once executed, the PowerShell loader installed the campaign’s malicious payloads and helped them achieve persistence. This loader behaved differently depending upon whether it had administrative privileges. In the event that it had these rights, it used its first URL to launch a Remcos remote access tool. Otherwise, this URL downloaded the DarkVNC remote-access tool. The campaign then loaded XMRigCC, a variant of an open-source cryptocurrency miner, before finally injecting an AZORult sample into the notepad.exe process.

A Busy Year for AZORult So Far

AZORult has been featured in numerous attack campaigns so far in 2020. Back in early February, for instance, SANS ISC detected a maldoc campaign that leveraged three layers of encryption to deliver a sample of the info-stealing malware family. About two weeks later, Kaspersky Lab spotted an attack in which malicious actors targeted Windows users with the Trojan via fake ProtonVPN installers.

Defend Against Attacks Abusing PowerShell

Security professionals can help their organizations defend against attacks that abuse PowerShell by disabling the use of this framework if there’s no business need for it. Companies should also consider implementing application whitelisting and restricting administrative access to only a necessary handful of machines to help curtail the spread of malware. Additionally, security teams should use a security information and event management (SIEM) tool and configure their solution to detect malicious PowerShell activity.

More from

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Protecting your digital assets from non-human identity attacks

4 min read - Untethered data accessibility and workflow automation are now foundational elements of most digital infrastructures. With the right applications and protocols in place, businesses no longer need to feel restricted by their lack of manpower or technical capabilities — machines are now filling those gaps.The use of non-human identities (NHIs) to power business-critical applications — especially those used in cloud computing environments or when facilitating service-to-service connections — has opened the doors for seamless operational efficiency. Unfortunately, these doors aren’t the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today