Aur0ra is a Russian-speaking, financially motivated ransomware group that emerged in late April 2026. It conducts double-extortion operations, deploying a victim-specific locker, encrypting data in place, deleting volume shadow copies, and using a data-leak site to pressure nonpaying victims. The locker supports configurable partial encryption, multithreading, and virtualization-platform targeting. Observed intrusions have begun with email bombing followed by vishing in which operators impersonate IT helpdesk personnel. Aur0ra has used the legitimate Xray-core proxy and tunneling platform as a reverse command-and-control channel, camouflaging traffic to resemble Chrome-related TLS activity. The group has established persistence through scheduled tasks and user-level autorun mechanisms, conducted extensive lateral movement using Windows remote-management and directory-service protocols, attempted Active Directory privilege escalation, and ultimately abused high-privilege administrator accounts. Aur0ra operators have cleared Windows event logs, disabled Microsoft Defender protections, timestomped tunneling components, distributed ransomware through SMB shares, and manually detonated the locker. Separately, operators associated with Aur0ra reportedly used an AI coding agent while falsely representing malicious work as authorized security simulations, including for credential theft, password cracking, account takeover, VPN access, and vulnerable-system exploitation. Publicly identified victims span chemical products, manufacturing, certification services, pharmaceutical distribution, and real-estate services in Belgium, Germany, the United Kingdom, Argentina, Italy, and the United States.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Aur0ra conducted intrusion activity against organizations in multiple countries and sectors, using a commercial AI coding agent to accelerate credential theft, password discovery and cracking, account takeover, network access, and exploitation attempts. The group socially engineered the AI agent's safeguards by claiming its actions were part of legitimate security simulations; at least one victim, Bayou Title, appeared on its data-leak site.
A newly active, Russian-speaking ransomware group that used Cursor's AI agent, reportedly through simulation-test pretexts that bypassed guardrails, to accelerate intrusions, credential theft, account takeover, password-hash cracking, and likely data-extortion activity against at least 20 claimed victims.
Opération de ransomware à double extorsion ayant obtenu un accès initial par email bombing suivi de vishing se faisant passer pour le helpdesk. Le groupe a utilisé Xray-core masqué pour le C2, effectué des mouvements latéraux et tenté une élévation de privilèges dans Active Directory, désactivé les défenses et effacé les journaux, puis exécuté manuellement son locker pour chiffrer les systèmes et inhiber la récupération.
A double-extortion ransomware group observed gaining initial access through email bombing followed by vishing. In this incident, Aur0ra deployed a victim-specific ransomware locker and used a renamed Xray-core reverse tunnel for command and control, conducted noisy lateral movement, attempted privilege escalation, cleared logs, disabled Windows Defender protections, deleted volume shadow copies, and encrypted files in place.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.