Security researchers spotted a multi-pronged attack campaign that delivered a variant of the AZORult family along with other malicious payloads. The attack instance observed by Cisco Talos downloaded a compressed version of the ISO image with ZIP onto the victims machine, a technique that indicates the attack likely originated from an email. This loader behaved differently depending upon whether it had administrative privileges or if it had the right to launch a remote-access tool. Companies should also consider implementing application whitelisting and restricting administrative access to only a few machines to help curtail the spread of malware.”]

