Azorult Trojan Steals Passwords While Hiding as Google Update

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
The AZORult information stealer and downloader malware strain was observed by Minerva Labs' research team posing as a signed Google Update installer and achieving persistence by replacing the legitimate Google Updater program on compromised machines

AZORult is an ever-evolving data-stealing Trojan also known to act as a downloader for other malware payloads in multi-stage campaigns and previously detected as part of highly complex and large scale malicious campaigns spreading ransomware, data and cryptocurrency stealing malware.

On its own, AZORult is designed to exfiltrate as much sensitive information as possible, from files, passwords, cookies, and browser history to banking credentials and cryptocurrency wallets once it successfully infects a targeted machine.


Stolen certificate used to sign the fake Google Update binary

According to Minerva Labs' Asaf Aprozper and Gal Bitensky, they received a GoogleUpdate.exe binary signed with a valid certificate from a customer which was blocked by Minerva’s Anti-Evasion Platform at launch. Everything about the GoogleUpdate.exe program pointed to it being a legitimate updater from Google, having the right icon and being signed with a non-revoked certificate.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top