HomeSecurityAZORult malware spreads via fake Google websites

AZORult malware spreads via fake Google websites

Cybersecurity researchers have discovered a new malware campaign that exploits fake Google Sites pages and HTML smugglingto distribute malware called AZORult, with the aim of facilitating information theft.

See also: Malware families adapt to COM Hijacking technique

AZORult malware

According to a report published last week , Netskope Threat Labs researcher Jan Michael Alcantara says it uses an HTML smuggling technique, where the malicious payload is embedded in a separate JSON file hosted on an external website.

The phishing campaign has not been attributed to a specific threat actor or group. The cybersecurity firm described it as wide-ranging, with the aim of collecting sensitive data for sale on malicious forums.

AZORult malware, also called PuffStealer and Ruzalto, is an information stealer first detected around 2016.It is typically distributed through phishing and malicious spam (malspam) campaigns, pirated software installers or trojanized media, and malicious advertising.

Once installed, the program is capable of collecting credentials, cookies , and history from web browsers , screenshots, documents matching a list of specific extensions ( .TXT, .DOC, .XLS, .DOCX, .XLSX, .AXX, and .KDBX ), and data from 137 cryptocurrency wallets. AXX files are encrypted files created by AxCrypt , while KDBX refers to a password database created by the KeePass password manager .

The most recent attack activity involves the threat actor creating fake Google Docs on Google Sites that then use HTML smuggling to deliver the payload.

See also: Mobile malware: A major risk for businesses

AZORult malware spreads via fake Google websites

HTML smuggling is a sneaky technique in which legitimate HTML5 and JavaScript are abused to assemble and launch malware, “hiding” a coded malicious script.

So, when a visitor falls victim by opening the fake page from a phishing email, the browser decodes the script and outputs the payload to the hosting device, effectively bypassing standard security checks like email gateways that only check for suspicious attachments.

The AZORult malware campaign goes a step further by implementing a CAPTCHA, an approach that not only gives an impression of legitimacy but also acts as an extra layer of protection against URL crawlers.

The file it downloads is a Windows shortcut file (.LNK) presented as a PDF bank statement excerpt, which initiates a series of actions to execute a series of intermediate PowerShell from an already compromised domain.

One of the PowerShell scripts (“agent3.ps1”) of the AZORult malware was designed to retrieve the AZORult loader (“service.exe”), which downloads and executes another PowerShell script (“sd2.ps1”) containing the malicious stealing program.

See also: Ande Loader malware targets the construction sector

How can one protect themselves from phishing attacks?

Protecting yourself from phishing attacks requires awareness and vigilance. First, it is important to regularly update computer , such as antivirus and anti-malware software. Second, you should be cautious about the emails you receive. Do not open attachments or click on links from unknown senders. Also, always check the sender's email address to make sure it is legitimate. Third, use strong passwords and change them regularly. Finally, it is important to stay up to date on the latest phishing techniques and educate yourself to recognize the signs of a phishing attack. Knowledge is the best defense.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS