Aurora Stealer is a Windows information-stealing malware family written in Go that emerged in 2022 and has been sold through a malware-as-a-service model on Russian-speaking criminal forums. It has been observed in financially motivated campaigns targeting organizations and individual users, including infections in the manufacturing sector, and is commonly delivered through malvertising and fake software download pages impersonating popular applications and vendors. Aurora Stealer has also been distributed through pay-per-install ecosystems and loader chains including HijackLoader, also tracked as IDAT Loader or RUGMI, and has appeared in campaigns associated with the SteelClover cluster.
Its core function is theft of sensitive data from infected systems. Aurora Stealer collects browser-stored credentials, cookies, autofill data, and other browser artifacts from Chromium-based browsers, and reporting also attributes theft of browser data from major browsers including Chrome, Edge, and Firefox in some deployment chains. It can steal cryptocurrency wallet data from numerous wallet applications, capture Telegram Desktop session data, take screenshots, and gather host profiling information such as operating system and hardware details. Later versions added theft of FTP and Remote Desktop credentials. The malware also includes grabber functionality for collecting attacker-selected files and folders.
Aurora Stealer supports additional post-compromise functionality beyond simple data theft. Builds have included an embedded loader capable of downloading and executing further payloads or launching PowerShell commands, and the broader service offering has advertised auxiliary modules for remote access, brute force, scanning, and DDoS-style botnet activity. Exfiltration is performed through structured communications with command-and-control infrastructure, with stolen data packaged and transmitted in encoded and compressed form. The malware also supports operator notifications through Telegram.
The family uses multiple evasion and deployment techniques. Reported samples use junk-byte padding, packing or crypting, and anti-analysis measures. Aurora Stealer is frequently delivered via fake installers promoted through Google Ads and other traffic acquisition methods, often masquerading as legitimate software such as text editors, remote administration tools, collaboration software, or hardware drivers. In other cases it is the final payload of multi-stage loader chains that use DLL sideloading, process injection, persistence mechanisms, and living-off-the-land execution to establish and protect execution before deploying the stealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Tactic Initial Access ID T1189 MITRE ATT&CK Technique Drive-by Compromise Description Aurora Stealer is delivered via a website hosting a fake software installer
It was distributed through a fake one-page website containing only two buttons... the “Download for Android” button leads to downloading samples of Ermac... modified legitimate application was downloaded from malicious website mimicking the original website of the application. Victim is navigated there through malicious advertisement.
Scheduled Task T1053.005 Persistence modTask64 module for scheduled task creation
The loader is simply used to download and execute a final payload
Scheduled Task T1053.005 Persistence modTask64 module for scheduled task creation
Modify Registry T1112 Defense Evasion Registry operations (inferred from modTask64)
Scheduled Task T1053.005 Persistence modTask64 module for scheduled task creation
COM Object Hijacking T1546.015 Persistence CoInitializeEx / CoCreateInstance usage
Obfuscated Files T1027 Defense Evasion LZNT1, AES/RC4 encryption, encrypted payload blob
MITRE ATT&CK Tactic Defense Evasion ID T1027.001 MITRE ATT&CK Technique Binary Padding Description Aurora Stealer contains the file pump feature upon creating the build to add null bytes to the stealer payload
This time it was another Windows Trojan stealer known as Aurora... more than 300 MB. This is probably a tactic to overcome detection by antivirus engines, as most of the data is just an “overlay” filled with zero bytes. At the same time the actual payload is encrypted and unpacked during the execution of the application.
These fake sites copy pages from the real software sites and have links to download the malware... the malware is hosted on a server impersonating the legitimate site obsproject.com .
The extracted 2nd stage is the golang stealer sold as "Aurora Stealer" ... def decrypt(data, key1, key2, key3): ... open(file_path + '_extracted.bin', 'wb').write(final_pe)
Signed Binary Proxy Exec T1218 Defense Evasion tcpvcon.exe, jpegoptim.exe (signed/legitimate) | System Binary Proxy Exec T1218 Defense Evasion MSBuild.exe for code execution
employs Living-off-the-Land (LoTL) techniques via MSBuild.exe... LoTL: MSBuild.exe (.NET v2/v4) for code execution
Il cible notamment les données des navigateurs (mots de passe, cookies, historiques, cartes bancaires)...
MITRE ATT&CK Tactic Credential Access ID T1555 T1555.003 MITRE ATT&CK Technique Credentials from Web Browsers Description Aurora Stealer steals sensitive data from browsers including credentials, cookies and saved credit cards as well as FTP and RDP credentials
MITRE ATT&CK Tactic Credential Access ID T1555 T1555.003 MITRE ATT&CK Technique Credentials from Web Browsers Description Aurora Stealer steals sensitive data from browsers including credentials, cookies and saved credit cards as well as FTP and RDP credentials
MITRE ATT&CK Tactic Discovery ID T1082 MITRE ATT&CK Technique System Information Discovery Description The stealer enumerates the host for hardware and geographical information as well as the screen size
File and Directory Discovery E1083/T1083 Discovery File system enumeration
Aurora Stealer has multiple Grabber functions that are responsible for collecting additional data such as crypto wallets, screenshots, files, Telegram, etc.
Post-infection traffic caused by this malware went to a server at 79.137.133[.]225 over TCP port 8081... Post-infection traffic consists of plain text.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer final payload that steals browser credentials, cookies/session tokens, cryptocurrency wallets, and files, and communicates with C2 using encrypted traffic.
Information-stealing malware written in Go that steals browser data, cookies, autofill data, encrypted passwords, crypto wallet data, Telegram desktop session data, screenshots, and additional files. It includes grabber and loader modules, can download and run secondary payloads or execute PowerShell commands, stores configuration in base64-encoded form, and exfiltrates logs to C2 over port 8081 in GZIP-compressed, base64-encoded JSON.
A Go-based information stealer delivered as the second-stage payload by the loader.
Google広告経由の他キャンペーンで配布されている情報窃取マルウェアとして言及されている。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.