Aurora Stealer is a Windows infostealer that evolved from an earlier botnet concept into a Malware-as-a-Service offering distributed in cybercriminal forums and deployed through multiple delivery ecosystems. It is used to steal browser-stored credentials, cookies, session tokens, cryptocurrency wallet data, and files, and it communicates with its operators using encrypted command-and-control data. Aurora Stealer has been observed as the final payload in loader chains associated with RUGMI, also tracked as HijackLoader and IDAT Loader, where multi-stage execution relies on aggressive DLL sideloading, runtime API resolution, process injection, and other defense-evasion techniques. Observed deployment chains have used legitimate signed binaries and Living-off-the-Land execution to launch malicious components, establish persistence, and inject into user processes. Related activity has also tied Aurora Stealer to malvertising campaigns using spoofed software-brand advertisements and lookalike sites. The malware primarily targets Windows systems and is associated with credential theft, session hijacking through cookie theft, cryptocurrency theft, file exfiltration, persistence, and post-exploitation activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Scheduled Task T1053.005 Persistence modTask64 module for scheduled task creation
Modify Registry T1112 Defense Evasion Registry operations (inferred from modTask64)
Scheduled Task T1053.005 Persistence modTask64 module for scheduled task creation
COM Object Hijacking T1546.015 Persistence CoInitializeEx / CoCreateInstance usage
Obfuscated Files T1027 Defense Evasion LZNT1, AES/RC4 encryption, encrypted payload blob
both Mozilla Thunderbird and Microsoft teams have been impersonated... including lookalike Nvidia domains
Deobfuscate/Decode T1140 Defense Evasion Runtime decryption of config and final payload
Il cible notamment les données des navigateurs (mots de passe, cookies, historiques, cartes bancaires)...
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer final payload that steals browser credentials, cookies/session tokens, cryptocurrency wallets, and files, and communicates with C2 using encrypted traffic.
Aurora Stealer is linked to fake Nvidia-themed domains used in Google Ad malvertising activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.