logo

Azorult Malware Abuses Google Sites To Steal Login Credentials

ID: 09a0fa82-a802-56c8-a225-20510cf8abf9

STIX ID: report--09a0fa82-a802-56c8-a225-20510cf8abf9

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2024-03-20

Date Updated: 2026-04-22

Author: Kayal Murugesan

...
...

A sophisticated Azorult campaign leverages HTML smuggling on Google Sites to deliver a JSON-hosted base64 payload which is executed filelessly using PowerShell reflective loading and an AMSI bypass; the malware (Azorult) runs in memory to harvest credentials, browser data, screenshots, and crypto wallet information before encrypting and exfiltrating it to a C2 server, with reported targeting of the healthcare sector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.