Aurora ransomware, also known as Aurora Locker, is a financially motivated ransomware operation active since approximately April 2026. The operation maintains a data-leak site and uses affiliate-led intrusions combining data theft, encryption, extortion, and payment collection. A documented direct affiliate was assessed as Russian-speaking and as following an apparent CIS-target exclusion policy, but this does not independently establish the group’s country of origin. Aurora operators conduct Active Directory-focused intrusions using valid or stolen credentials, internal reconnaissance, network and service scanning, Kerberoasting, AS-REP Roasting, NTLM coercion and relay, and Active Directory Certificate Services abuse. Observed activity also includes SQL Server command execution, privilege escalation to SYSTEM, DCSync credential theft, proxy-based network access, and data staging in large archives before exfiltration to attacker-controlled S3-compatible storage. Operators have used AI-assisted coding-agent workflows to support post-compromise reconnaissance, privilege enumeration, network scanning, proxy configuration, NTLM-relay attempts, and certificate attacks. Aurora deploys Windows and Linux encryptors built from a shared Zig codebase. Its Linux variant targets VMware ESXi environments, forcibly stops virtual machines before encrypting virtual-machine files, and preserves ESXi system volumes so the hypervisor remains bootable and can present an extortion message through the SSH login process. Windows activity includes recovery-inhibition actions such as deletion of Volume Shadow Copies and disabling System Restore. Aurora has targeted organizations across manufacturing, technology, financial and professional services, retail and consumer goods, transport and logistics, and construction sectors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed ransomware attack and data breach affecting electronics distributor Chip 1 Exchange, involving alleged exfiltration of employee identity and payroll records, financial information, manufacturer agreements, defense-related sales orders, and Outlook email archives.
Aurora is a Russian-speaking ransomware operation whose direct affiliate conducted end-to-end intrusions, including Active Directory reconnaissance and privilege escalation, credential attacks, data exfiltration, victim-specific ransom negotiations, and Windows and Linux/ESXi encryption. The affiliate avoided CIS targets and used shared laundering infrastructure for cryptocurrency proceeds.
Opération de ransomware à double extorsion ciblant des organisations internationales. Aurora déploie notamment une variante Linux/ESXi pour chiffrer des environnements VMware, utilise des outils d’administration et de découverte réseau, mène des attaques NTLM relay et AD CS, et exfiltre des données vers du stockage S3 auto-hébergé. Un cluster distinct attribué avec une confiance moyenne a aussi utilisé SQL Server xp_cmdshell, GodPotato et DCSync.
A ransomware group active since April 2026 that targets organizations globally, operates a data-leak site, and used an AI coding-agent workflow to support post-compromise reconnaissance, network access operations, certificate attacks, and deployment of a Linux ransomware variant against VMware ESXi environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.