FILEMembers
FILE

Meteorite Downloader Delivers Azorult and OskiStealer to Media Targets

A Varist-packed dropper self-identifying as 'Meteorite Downloader v3.01' has been observed targeting media organisations in Canada, France, and the United States. The campaign delivers Azorult and OskiStealer credential-theft payloads through a layered evasion stack combining timing-based sandbox defeat, three concurrent process-injection sub-techniques, and active suppression of security tooling. Eleven domains across three structurally distinct infrastructure clusters support the operation.

Jun 22, 2026, 18:17 (UTC+9)Last seenJun 22, 2026Severity100ByCTX TeamIOC17MITRE21RegionsCAFRUS

A Varist-packed dropper self-identifying as "Meteorite Downloader v3.01" has been observed targeting media organisations in Canada, France, and the United States, delivering Azorult and OskiStealer credential-theft payloads through a layered evasion stack that combines timing-based sandbox defeat, three concurrent process-injection sub-techniques, and active suppression of security tooling.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence