Aura Stealer
Aliases: AURA Stealer, AURASTEAL
- Malware type
- credential-stealer, loader
- Family
- Malware family
- Last IoC activity
- 2026-07-21 04:36:46
- Profile updated
- 2026-07-07 14:46:23
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
In July 2025, threat actor AuraCorp began advertising Aura Stealer as a Malware-as-a-Service (MaaS) program with multiple subscription tiers on underground forums. The information stealer targets credentials from over 110 browsers, 70 applications, and 250+ browser extensions, including cryptocurrency wallets and 2FA tools, while using AES-256 encryption for C2 communications. Notable features include seamless Chromium cookie harvesting without process termination, server-side App-Bound data decryption, and a built-in payload loader with custom morphing for detection evasion.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Aurastealer (report)
- blog.xyris.mov — Aura Stealer %232 Beatin The Obfuscation (report)
- intrinsec.com — Tlp Clear Aurastealer En (report)
- gendigital.com — Defeating Aurastealer Obfuscation (report)
- blog.xyris.mov — Aura Stealer %231 36Bytesmademelosemymind (report)
- foresiet.com — Aura Stealer Malware Analysis (report)