aurora
Aliases: OneKeyLocker
- First seen
- 2019-05-15 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-21 16:30:19
- Profile updated
- 2026-07-07 14:02:37
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:gb country_code:de
Context
Aurora, also known as OneKeyLocker, is a ransomware family targeting multiple sectors including financial services and public sector entities. It encrypts victim data and demands payment for the decryption key, predominantly affecting targets in the US, UK, and Germany.
Detection coverage
- 4 YARA rules
Detection rules
- MALPEDIA_Win_Aurora_Auto (yara-rule)
- DITEKSHEN_MALWARE_Win_Aurora (yara-rule)
- SEKOIA_Infostealer_Win_Aurora (yara-rule)
- SEKOIA_Infostealer_Win_Aurora_Str (yara-rule)
Related threat objects
- Hydraq (malware)
Reports & references
- ransomlook.io — Aurora (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Aurora (report)
- blog.morphisec.com — In2Al5D P3In4Er (report)
- bleepingcomputer.com — Azorult Trojan Serving Aurora Ransomware By Malactor Oktropys (report)
- twitter.com — 1001461507513880576 (report)
- bleepingcomputer.com — How To Decrypt The Aurora Ransomware With Auroradecrypter (report)