Aurora Stealer is a Windows information-stealing malware family written in Go that emerged in 2022 and has been marketed as a malware-as-a-service offering on Russian-speaking criminal forums. It has been associated with financially motivated cybercrime activity and is commonly delivered through malvertising and fake software download pages impersonating popular applications and vendors. Observed delivery chains have included spoofed installer pages promoted through Google Ads, pay-per-install ecosystems such as HijackLoader/IDAT Loader, and other loader-based distribution arrangements.
Aurora Stealer focuses on collecting sensitive user and host data. Core functionality includes theft of browser credentials, cookies, autofill data, and other stored browser artifacts; collection of cryptocurrency wallet data from numerous wallet applications; theft of Telegram Desktop session data; screenshot capture; and host profiling through system reconnaissance. Reported updates expanded credential theft to include FTP and RDP data. The malware can also archive attacker-selected files through a grabber component and supports exfiltration of stolen data to operator-controlled infrastructure using structured, compressed, and encoded communications.
Aurora Stealer includes modular post-compromise functionality beyond pure information theft. Documented builds contain a loader component capable of downloading and executing additional payloads or launching PowerShell commands, enabling follow-on malware deployment and broader post-exploitation activity. Public reporting has also described Aurora ecosystem offerings that advertised auxiliary modules such as remote access, brute-force, scanning, and DDoS capabilities, although the stealer payload itself is primarily characterized by credential and data theft.
The malware employs multiple evasion measures, including packing or crypting options, junk-byte padding, runtime configuration storage in encoded form, and temporary staging of stolen data before exfiltration. In some delivery chains, Aurora has been deployed through multi-stage loaders that use DLL sideloading, process injection, persistence mechanisms, and anti-analysis checks before launching the final stealer payload.
Victimology has included manufacturing organizations and users seeking common software downloads, with campaigns observed across fake pages themed around developer tools, remote administration software, communications software, and hardware drivers. Aurora Stealer is part of the broader commodity infostealer ecosystem and is frequently used in opportunistic, financially motivated intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Tactic Initial Access ID T1189 MITRE ATT&CK Technique Drive-by Compromise Description Aurora Stealer is delivered via a website hosting a fake software installer
It was distributed through a fake one-page website containing only two buttons... the “Download for Android” button leads to downloading samples of Ermac... modified legitimate application was downloaded from malicious website mimicking the original website of the application. Victim is navigated there through malicious advertisement.
Scheduled Task T1053.005 Persistence modTask64 module for scheduled task creation
The loader is simply used to download and execute a final payload
Scheduled Task T1053.005 Persistence modTask64 module for scheduled task creation
Modify Registry T1112 Defense Evasion Registry operations (inferred from modTask64)
Scheduled Task T1053.005 Persistence modTask64 module for scheduled task creation
COM Object Hijacking T1546.015 Persistence CoInitializeEx / CoCreateInstance usage
Obfuscated Files T1027 Defense Evasion LZNT1, AES/RC4 encryption, encrypted payload blob
MITRE ATT&CK Tactic Defense Evasion ID T1027.001 MITRE ATT&CK Technique Binary Padding Description Aurora Stealer contains the file pump feature upon creating the build to add null bytes to the stealer payload
This time it was another Windows Trojan stealer known as Aurora... more than 300 MB. This is probably a tactic to overcome detection by antivirus engines, as most of the data is just an “overlay” filled with zero bytes. At the same time the actual payload is encrypted and unpacked during the execution of the application.
The extracted 2nd stage is the golang stealer sold as "Aurora Stealer" ... def decrypt(data, key1, key2, key3): ... open(file_path + '_extracted.bin', 'wb').write(final_pe)
Signed Binary Proxy Exec T1218 Defense Evasion tcpvcon.exe, jpegoptim.exe (signed/legitimate) | System Binary Proxy Exec T1218 Defense Evasion MSBuild.exe for code execution
employs Living-off-the-Land (LoTL) techniques via MSBuild.exe... LoTL: MSBuild.exe (.NET v2/v4) for code execution
Il cible notamment les données des navigateurs (mots de passe, cookies, historiques, cartes bancaires)...
MITRE ATT&CK Tactic Credential Access ID T1555 T1555.003 MITRE ATT&CK Technique Credentials from Web Browsers Description Aurora Stealer steals sensitive data from browsers including credentials, cookies and saved credit cards as well as FTP and RDP credentials
MITRE ATT&CK Tactic Credential Access ID T1555 T1555.003 MITRE ATT&CK Technique Credentials from Web Browsers Description Aurora Stealer steals sensitive data from browsers including credentials, cookies and saved credit cards as well as FTP and RDP credentials
MITRE ATT&CK Tactic Discovery ID T1082 MITRE ATT&CK Technique System Information Discovery Description The stealer enumerates the host for hardware and geographical information as well as the screen size
File and Directory Discovery E1083/T1083 Discovery File system enumeration
Aurora Stealer has multiple Grabber functions that are responsible for collecting additional data such as crypto wallets, screenshots, files, Telegram, etc.
Post-infection traffic caused by this malware went to a server at 79.137.133[.]225 over TCP port 8081... Post-infection traffic consists of plain text.
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer final payload that steals browser credentials, cookies/session tokens, cryptocurrency wallets, and files, and communicates with C2 using encrypted traffic.
Information-stealing malware written in Go that steals browser data, cookies, autofill data, encrypted passwords, crypto wallet data, Telegram desktop session data, screenshots, and additional files. It includes grabber and loader modules, can download and run secondary payloads or execute PowerShell commands, stores configuration in base64-encoded form, and exfiltrates logs to C2 over port 8081 in GZIP-compressed, base64-encoded JSON.
A Go-based information stealer delivered as the second-stage payload by the loader.
Google広告経由の他キャンペーンで配布されている情報窃取マルウェアとして言及されている。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.