Azorult Malware Abuses Google Sites To Steal Login Credentials
ID: 09a0fa82-a802-56c8-a225-20510cf8abf9
STIX ID: report--09a0fa82-a802-56c8-a225-20510cf8abf9
Feed Name: GBHackers
Threat Score
A sophisticated Azorult campaign leverages HTML smuggling on Google Sites to deliver a JSON-hosted base64 payload which is executed filelessly using PowerShell reflective loading and an AMSI bypass; the malware (Azorult) runs in memory to harvest credentials, browser data, screenshots, and crypto wallet information before encrypting and exfiltrating it to a C2 server, with reported targeting of the healthcare sector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
