Gazavat is a Rust-based information stealer first documented by SentinelOne in August 2023, attributed to the financially motivated threat group TA547. It is categorized as a credential stealer and clipper malware designed to intercept cryptocurrency transactions and exfiltrate browser-stored passwords.
Gazavat propagates via spear-phishing emails containing malicious LNK or ISO attachments that download its main payload from a hardcoded URL. Its command-and-control (C2) infrastructure uses the Discord API over WebSocket for real-time data exfiltration, bypassing traditional HTTP monitoring. Persistence is achieved through a scheduled task named “GazavatUpdate” that runs the executable at user logon. Evasion techniques include checking for sandbox environments by detecting virtualization artifacts (e.g., vmtoolsd.exe) and terminating if found. The malware employs process hollowing into legitimate Windows processes such as svchost.exe to evade endpoint detection. It also clears Windows Event Logs using the wevtutil command after exfiltration.
Gazavat was first observed in the wild targeting cryptocurrency users in Eastern Europe during Q2 2023. In September 2023, a campaign attributed to TA547 compromised over 500 victims by hijacking clipboard content to replace wallet addresses. No high-profile corporate victims have been publicly named, and no CVEs have been associated with this malware. Law enforcement has not yet taken direct action against the group.
Known SHA256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (malicious payload DDL). Behavioral indicators include creation of the mutex GazavatMutex upon first execution. Network IOCs include User-Agent strings beginning with “Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gazavat/1.0” and HTTPS connections to Discord CDN subdomains with high-frequency clipboard data uploads.
Gazavat primarily causes financial losses by replacing cryptocurrency wallet addresses in clipboard contents, redirecting funds to threat actors. It also exfiltrates browser credentials, potentially leading to account takeovers and identity theft. The malware has overwhelmingly affected individual cryptocurrency traders and small businesses in the fintech sector.
Recommended mitigations include blocking execution of LNK and ISO files downloaded from the internet via Windows Defender Attack Surface Reduction rules, and deploying detection rules for the “GazavatMutex” mutex and Discord API outbound connections using EDR tools such as Microsoft Defender for Endpoint or SentinelOne. No specific patch is required as the malware does not exploit a known vulnerability.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.