
Meteorite Downloader Delivers Azorult and OskiStealer to Media Targets
A Varist-packed dropper self-identifying as 'Meteorite Downloader v3.01' has been observed targeting media organisations in Canada, France, and the United States. The campaign delivers Azorult and OskiStealer credential-theft payloads through a layered evasion stack combining timing-based sandbox defeat, three concurrent process-injection sub-techniques, and active suppression of security tooling. Eleven domains across three structurally distinct infrastructure clusters support the operation.
A Varist-packed dropper self-identifying as "Meteorite Downloader v3.01" has been observed targeting media organisations in Canada, France, and the United States, delivering Azorult and OskiStealer credential-theft payloads through a layered evasion stack that combines timing-based sandbox defeat, three concurrent process-injection sub-techniques, and active suppression of security tooling.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read