February 19, 2020 By David Bisson 2 min read

Security researchers observed the AZORult Trojan using a fake ProtonVPN installer to prey upon Windows users.

In mid-February, Kaspersky spotted a campaign in which digital attackers abused the ProtonVPN service to trick Windows users. Researchers at the security firm witnessed the campaign using malvertising techniques via affiliation banner networks as one of its infection vectors. These tactics tricked users into visiting counterfeit websites and downloading a fake ProtonVPN installer for Windows. Once downloaded, those installers infected users with the AZORult botnet.

Upon execution, the malware collected the environment information of the infected machine and sent it off to its command-and-control (C&C) server located at accounts[.]protonvpn[.]store. Malicious actors then used AZORult to steal various other details from their victims, including FTP logins, passwords, email credentials and even cryptocurrency from users’ local wallets.

AZORult’s Ongoing Evolution

News of this campaign comes after several rounds of innovation on the part of AZORult. Back in October 2018, for instance, Check Point observed a fresh version of the malware that came with a new means of connecting to its C&C server, an improved cryptocurrency wallet stealer and other changes.

This discovery came at around the same time that Palo Alto Networks spotted the malware as one of the primary payloads of the Fallout exploit kit in a campaign that researchers called “FindMyName.” More than a year later in February 2020, SANS’ Internet Storm Center discovered a campaign that used a triple-encrypted downloader to target users with AZORult.

How to Fend Off Fake ProtonVPN Malvertisements

Security professionals can help defend their organizations against malvertising campaigns, including those that use fake ProtonVPN installers, by keeping an eye on malvertising strategies and using threat intelligence to stay abreast of the latest campaigns leveraging these tactics.

Acknowledging malefactors’ frequent use of exploit kits in malvertising attacks, infosec personnel should also thoughtfully prioritize their organizations’ systems and functions so that they can create and maintain an effective patching schedule.

More from

How prepared are you for your first Gen AI disruption?

5 min read - Generative artificial intelligence (Gen AI) and its use by businesses to enhance operations and profits are the focus of innovation in virtually every sector and industry. Gartner predicts that global spending on AI software will surge from $124 billion in 2022 to $297 billion by 2027. Businesses are upskilling their teams and hiring costly experts to implement new use cases, new ways to leverage data and new ways to use open-source tooling and resources. What they have failed to look…

Cybersecurity crisis communication: What to do

4 min read - Cybersecurity experts tell organizations that the question is not if they will become the target of a cyberattack but when. Often, the focus of response preparedness is on the technical aspects — how to stop the breach from continuing, recovering data and getting the business back online. While these tasks are critical, many organizations overlook a key part of response preparedness: crisis communication.Because a brand’s reputation often takes a significant hit, a cyberattack can significantly affect the company’s future success…

Brands are changing cybersecurity strategies due to AI threats

3 min read -  Over the past 18 months, AI has changed how we do many things in our work and professional lives — from helping us write emails to affecting how we approach cybersecurity. A recent Voice of SecOps 2024 study found that AI was a huge reason for many shifts in cybersecurity over the past 12 months. Interestingly, AI was both the cause of new issues as well as quickly becoming a common solution for those very same challenges.The study was conducted…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today