Aurora Stealer is an infostealer delivered in the observed case as the final payload of the RUGMI/HijackLoader malware ecosystem, also tracked as IDAT Loader, a malware-as-a-service/pay-per-install loader active since 2023. In the analyzed chain, a fully decrypted Stage 4 payload used aggressive DLL sideloading with legitimate signed binaries including Sysinternals tcpvcon.exe and a jpegoptim-themed launcher (EngineX-Aurora.exe disguised as jpegoptim.exe), DLL search order hijacking via malicious pla.dll and d3d9.dll/Register.dll, Living-off-the-Land execution through MSBuild.exe, process injection into explorer.exe, persistence via %LOCALAPPDATA%\RaScope.exe and the Windows Startup folder, and reportedly included modules for UAC bypass and scheduled task creation. The Aurora payload is assessed to steal browser credentials from Chrome, Firefox, and Edge, harvest cookies and session tokens, steal cryptocurrency wallets, and exfiltrate files. Its command-and-control configuration was stored in a high-entropy encrypted blob and could not be statically recovered without the runtime decryption key, indicating encrypted C2 communications. The analyzed sample contained campaign identifier xy_Alt_betav1 and a PDB path in EngineX-Aurora.exe exposing the username xmr. Reported artifacts from this deployment include stage_4_decrypted_payload.bin (SHA256 c89f99602d833822c0954ac0266580919816da23b2adeb820dcf8b5639afb04a), tcpvcon.exe (SHA256 e202f137869cce7fdea6b6cd1169f5e0b6a46cc2d89265a31f63484b0f48bb29), tinystub64.bin/Register.dll (SHA256 729e5965e43ff458f6da901536c9a43be52a3820718e2dd5456150e2d73bb97f), and EngineX-Aurora.exe (SHA256 c52664283a0dc2c3d500b236ce2d5379802c0d74d903da6b3e133b2de6e77949). Related IDAT Loader campaigns have targeted Ukrainian organizations. Separately, Spamhaus researchers linked fake Nvidia lookalike domains used in Google Ad malvertising to Aurora Stealer and Vidar, indicating malvertising as an additional observed delivery vector.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Scheduled Task T1053.005 Persistence modTask64 module for scheduled task creation
Modify Registry T1112 Defense Evasion Registry operations (inferred from modTask64)
Scheduled Task T1053.005 Persistence modTask64 module for scheduled task creation
COM Object Hijacking T1546.015 Persistence CoInitializeEx / CoCreateInstance usage
Obfuscated Files T1027 Defense Evasion LZNT1, AES/RC4 encryption, encrypted payload blob
both Mozilla Thunderbird and Microsoft teams have been impersonated... including lookalike Nvidia domains
Deobfuscate/Decode T1140 Defense Evasion Runtime decryption of config and final payload
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer final payload that steals browser credentials, cookies/session tokens, cryptocurrency wallets, and files, and communicates with C2 using encrypted traffic.
Aurora Stealer is linked to fake Nvidia-themed domains used in Google Ad malvertising activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.