logo

Multistage Loader used to spread AZORult and NanoCore

ID: 0b9baaf6-ce1c-580f-a47e-6891b2bc5edb

STIX ID: report--0b9baaf6-ce1c-580f-a47e-6891b2bc5edb

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ report documents an active multistage campaign (Mar 2020) distributing AZORult and NanoCore via malicious PowerPoint macros that fetch obfuscated scripts from Pastebin and use mshta, VBScript, PowerShell, and a .NET 'FreeDom' loader to inject infostealer payloads (process hollowing into notepad.exe); it includes persistence behaviors, updated encoding variants, IOCs (MD5s, C2 IPs, Pastebin users), and regional targeting (South Korea, Indonesia).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.