Aurora Ransomware

Aliases: Zorro Ransomware

Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:25:16

Context

Typical ransom software, Aurora virus plays the role of blackmailing PC operators. It encrypts files and the encryption cipher it uses is pretty strong. After encryption, the virus attaches .aurora at the end of the file names that makes it impossible to open the data. Thereafter, it dispatches the ransom note totaling 6 copies, without any change to the main objective i.e., victims must write an electronic mail addressed to [email protected] while stay connected until the criminals reply telling the ransom amount.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Aurora (yara-rule)

Reports & references

  • bleepingcomputer.com — The Week In Ransomware June 8Th 2018 Crybrazil Cryptconsole And Magniber (report)
  • spamfighter.com — News 21588 Aurora Ransomware Circulating The Cyber Space (report)
  • twitter.com — 1004435398687379456 (report)
  • bleepingcomputer.com — Aurora Zorro Ransomware Actively Being Distributed (report)
  • id-ransomware.blogspot.com — Aurora Ransomware (report)

External references