Aurora Stealer

First seen
2022-04-01 00:00:00
Malware type
credential-stealer, downloader, loader, screen-capture, spyware
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 14:07:52

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Context

First advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in April 2022, Aurora Stealer is a Golang-based information stealer with downloading and remote access capabilities. The malware targets data from multiple browsers, cryptocurrency wallets, local systems, and act as a loader. During execution, the malware runs several commands through WMIC to collect basic host information, snaps a desktop image, and exfiltrates data to the C2 server within a single base64-encoded JSON file.

Reports & references

  • info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
  • denshiyurei.medium.com — Silent Echoes The Hidden Dialogue Among Malware Entities Spotlight On Amos Infostealer 6D7Cd70E3219 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Aurora Stealer (report)
  • esentire.com — Esentire Threat Intelligence Malware Analysis Aurora Stealer (report)
  • blog.sekoia.io — Bluefox Information Stealer Traffer Maas (report)
  • d01a.github.io — Aurora Stealer Builder (report)
  • research.loginsoft.com — Aurora The Dark Dawn And Its Menacing Effects (report)
  • isc.sans.edu — 29448 (report)
  • research.openanalysis.net — In2Al5Dp3In4Er (report)
  • d01a.github.io — Aurora Stealer (report)
  • blog.sekoia.io — Aurora A Rising Stealer Flying Under The Radar (report)

External references