Aurora is a ransomware threat actor active by at least mid-2026 and publicly associated with intrusions against organizations in technology, construction, healthcare, financial services, manufacturing, transportation, and energy-adjacent sectors. Reported victims include organizations in the Netherlands, Germany, and the United States, indicating opportunistic multi-sector targeting rather than a narrowly specialized victim profile. Aurora has been linked to ransomware incidents that also involve substantial data theft. Reported compromises include exfiltration of source code repositories and version history, production database backups, employee and HR records, payroll and accounting data, banking information, project and bid records, engineering and operational data, customer datasets, and large enterprise file shares. This pattern supports the use of data-theft extortion and broader post-compromise collection activity in addition to ransomware deployment. Observed victim reporting indicates Aurora conducts post-exploitation actions focused on locating and extracting high-value business information from file servers, enterprise application servers, development environments, and backup stores. The actor has been associated with theft of proprietary software source code, database contents, operational documentation, financial records, and sensitive internal business data. In several cases, the actor reportedly accessed large volumes of enterprise data spanning multiple departments and subsidiaries, consistent with deep network access before extortion or public leak claims. Aurora is best characterized as a financially motivated ransomware and extortion actor. Available reporting supports exfiltration as a core capability and indicates operations centered on monetizing stolen corporate data and ransomware pressure against victim organizations. Publicly reported aliases beyond the name Aurora are not established in the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack and data theft against Pyramid Analytics B.V., claiming to have obtained source code, SQL Server production database backups, and customer data.
Conducting a ransomware attack and data exfiltration against Primed Halberstadt Medizintechnik, a German medical device manufacturer.
A ransomware group claimed or was reported as hitting Corporación Primax S.A.
Conducting a ransomware attack against Aerospace & Advanced Composites GmbH.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.