28 January 19, 18:05
Quote:The AZORult information stealer and downloader malware strain was observed by Minerva Labs' research team posing as a signed Google Update installer and achieving persistence by replacing the legitimate Google Updater program on compromised machines.
AZORult is an ever-evolving data-stealing Trojan also known to act as a downloader for other malware payloads in multi-stage campaigns and previously detected as part of highly complex and large scale malicious campaigns spreading ransomware, data and cryptocurrency stealing malware.
On its own, AZORult is designed to exfiltrate as much sensitive information as possible, from files, passwords, cookies, and browser history to banking credentials and cryptocurrency wallets once it successfully infects a targeted machine.
Source: https://www.bleepingcomputer.com/news/se...le-update/
Full Report by Minerva Labs: https://blog.minerva-labs.com/azorult-no...gle-update