aurora

Aliases: OneKeyLocker

First seen
2019-05-15 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-21 16:30:19
Profile updated
2026-07-07 14:02:37

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:gb country_code:de

Context

Aurora, also known as OneKeyLocker, is a ransomware family targeting multiple sectors including financial services and public sector entities. It encrypts victim data and demands payment for the decryption key, predominantly affecting targets in the US, UK, and Germany.

Detection coverage

  • 4 YARA rules

Detection rules

  • MALPEDIA_Win_Aurora_Auto (yara-rule)
  • DITEKSHEN_MALWARE_Win_Aurora (yara-rule)
  • SEKOIA_Infostealer_Win_Aurora (yara-rule)
  • SEKOIA_Infostealer_Win_Aurora_Str (yara-rule)

Related threat objects

Reports & references

  • ransomlook.io — Aurora (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Aurora (report)
  • blog.morphisec.com — In2Al5D P3In4Er (report)
  • bleepingcomputer.com — Azorult Trojan Serving Aurora Ransomware By Malactor Oktropys (report)
  • twitter.com — 1001461507513880576 (report)
  • bleepingcomputer.com — How To Decrypt The Aurora Ransomware With Auroradecrypter (report)

External references