Aurora Stealer
- First seen
- 2022-04-01 00:00:00
- Malware type
- credential-stealer, downloader, loader, screen-capture, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 14:07:52
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
First advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in April 2022, Aurora Stealer is a Golang-based information stealer with downloading and remote access capabilities. The malware targets data from multiple browsers, cryptocurrency wallets, local systems, and act as a loader. During execution, the malware runs several commands through WMIC to collect basic host information, snaps a desktop image, and exfiltrates data to the C2 server within a single base64-encoded JSON file.
Reports & references
- info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
- denshiyurei.medium.com — Silent Echoes The Hidden Dialogue Among Malware Entities Spotlight On Amos Infostealer 6D7Cd70E3219 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Aurora Stealer (report)
- esentire.com — Esentire Threat Intelligence Malware Analysis Aurora Stealer (report)
- blog.sekoia.io — Bluefox Information Stealer Traffer Maas (report)
- d01a.github.io — Aurora Stealer Builder (report)
- research.loginsoft.com — Aurora The Dark Dawn And Its Menacing Effects (report)
- isc.sans.edu — 29448 (report)
- research.openanalysis.net — In2Al5Dp3In4Er (report)
- d01a.github.io — Aurora Stealer (report)
- blog.sekoia.io — Aurora A Rising Stealer Flying Under The Radar (report)