AZORult spreads as a fake ProtonVPN installer
#1
Exclamation 
Quote:
[Image: azorult_protonvpn_01.png]

AZORult has its history. However, a few days ago, we discovered what appears to be one of its most unusual campaigns: abusing the ProtonVPN service and dropping malware via fake ProtonVPN installers for Windows.

The campaign started at the end of November 2019 when the threat actor behind it registered a new domain under the name protonvpn[.]store. The Registrar used for this campaign is from Russia.

We have found that at least one of the infection vectors is through affiliation banners networks (Malvertising).

When the victim visits a counterfeit website and downloads a fake ProtonVPN installer for Windows, they receive a copy of the Azorult botnet implant.

[Image: azorult_protonvpn_02.png]

The Website is an HTTrack copy of the original ProtonVPN website as shown below.

Once the victim runs the implant, it collects the infected machine’s environment information and reports it to the C2, located on the same accounts[.]protonvpn[.]store server.

In their greed, the threat actors have designed the malware to steal cryptocurrency from locally available wallets (Electrum, Bitcoin, Etherium, etc.), FTP logins and passwords from FileZilla, email credentials, information from locally installed browsers (including cookies), credentials for WinSCP, Pidgin messenger and others.

We have been able to identify a few samples associated with the campaign.

Kaspersky products detect this threat as HEUR:Trojan-PSW.Win32.Azorult.gen.
...
Continue Reading
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Messages In This Thread
AZORult spreads as a fake ProtonVPN installer - by harlan4096 - 18 February 20, 11:13

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
LibreOffice 26.2.4
Berlin, 5 June 202...harlan4096 — 12:17
Surfshark VPN : Award-winning VPN servi...
Surfshark Apps Ver...jasonX — 11:34
K-Lite Codec Pack 19.7.5 / 19.7.5 Update
Changes in 19.7.5 ...harlan4096 — 10:19
Brave v1.91.168 (Chromium 149.0.7827.54)
Release v1.91.168 ...harlan4096 — 10:17
Vivaldi 8.0 Build 4033.44
Vivaldi 8.0 Build ...harlan4096 — 10:16

[-]
Birthdays
Today's Birthdays
avatar (42)tapedDow
Upcoming Birthdays
avatar (48)BrantgoG
avatar (49)rapedDow
avatar (44)Johnsonsyday
avatar (49)Groktus
avatar (41)efodo
avatar (39)Tedscolo
avatar (46)brakasig
avatar (51)smudloquask
avatar (46)benchJem
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (42)zacforat
avatar (47)NemrokReks
avatar (38)Barrackleve
avatar (40)Julioagopy
avatar (50)aolaupitt2558
avatar (48)vadimTob
avatar (38)leannauu4
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>