Aurora, also referred to as Aurora Locker, is a financially motivated ransomware operation active since approximately April 2026. It targets organizations internationally across manufacturing, transportation and logistics, professional and financial services, technology, retail, consumer goods, chemicals, and healthcare. Aurora maintains a data-leak site and victim-negotiation infrastructure, combining data theft with encryption and threats of public disclosure. Its affiliate model includes operators responsible for the intrusion lifecycle through extortion and payment collection, with individually negotiated revenue splits. At least one affiliate is Russian-speaking; the operation's country of origin is not established. Aurora intrusions emphasize Active Directory compromise. Observed techniques include LDAP and SMB reconnaissance with NetExec, AS-REP roasting, Kerberoasting, noPac exploitation, Active Directory Certificate Services abuse, and coerced authentication followed by NTLM relay. Operators use remote services and SOCKS proxy pivots to traverse victim networks, archive stolen information before exfiltration, and identify VMware ESXi and vCenter infrastructure for ransomware deployment. Aurora operators have used Cursor Agent with Claude Sonnet to assist post-compromise reconnaissance and exploitation, including internal scanning, privilege enumeration, certificate attacks, NTLM relay attempts, and VPN or proxy configuration. These workflows require operator direction and iterative refinement rather than consistently autonomous execution. Aurora deploys Windows and Linux/ESXi encryptors written in Zig. The Windows variant inhibits recovery by deleting Volume Shadow Copies and disabling System Restore. The ESXi variant forcibly stops virtual machines and encrypts their files using ChaCha20 with RSA-4096 key protection. It preserves hypervisor system volumes to retain bootability and presents ransom demands through an SSH login banner.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Aurora claimed responsibility for breaching Thomas Y. Pickett & Co., Inc. and threatened to publish stolen information unless the firm met its demands. The reportedly stolen data includes SQL Server database backups, HR records, source code, and client contracts. The content reports the group's claims but does not independently establish the intrusion method or confirm file encryption.
Reportedly conducted a ransomware attack against Danish media-monitoring company Infomedia A/S, discovered on October 5, 2026. The report describes exposed database administrator credentials, a TLS private key, employee salary records, and 30 GB of financial data. It provides no independent attribution evidence or details of the initial intrusion.
Aurora claims to have exposed data belonging to Infomedia A/S, a Danish media-monitoring company first listed on October 5, 2026. The post identifies 30 GB of finance data, salary records for more than 100 employees, SQL Server administrator credentials, and an API TLS private key; no ransom amount or deadline is stated.
Aurora claims to have compromised Thomas Y. Pickett & Co., Inc., a US property tax appraisal consultancy listed as discovered on October 5, 2026. The post inventories 127 GB of database backups and an 11 GB source-code repository, alongside employee identity and medical records, credentials, client contracts, financial records, and a digital-signing private key; no ransom amount or deadline is stated.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.