Aurora Ransomware
Aliases: Zorro Ransomware
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:25:16
Context
Typical ransom software, Aurora virus plays the role of blackmailing PC operators. It encrypts files and the encryption cipher it uses is pretty strong. After encryption, the virus attaches .aurora at the end of the file names that makes it impossible to open the data. Thereafter, it dispatches the ransom note totaling 6 copies, without any change to the main objective i.e., victims must write an electronic mail addressed to [email protected] while stay connected until the criminals reply telling the ransom amount.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Aurora (yara-rule)
Reports & references
- bleepingcomputer.com — The Week In Ransomware June 8Th 2018 Crybrazil Cryptconsole And Magniber (report)
- spamfighter.com — News 21588 Aurora Ransomware Circulating The Cyber Space (report)
- twitter.com — 1004435398687379456 (report)
- bleepingcomputer.com — Aurora Zorro Ransomware Actively Being Distributed (report)
- id-ransomware.blogspot.com — Aurora Ransomware (report)