Auraboros C2 is a previously undocumented command-and-control framework. Researchers identified a live Auraboros C2 server at 174.138.43[.]25 hosted on DigitalOcean (AS14061), exposing an unauthenticated HTTP management panel on port 5000, a likely beacon listener or stager on port 9000, and a reverse SOCKS5 service on port 1080. The panel, branded as "Auraboros C2 Station" and "Auraboros Advanced Defense Systems," was written in Brazilian Portuguese and built with Express.js, Socket.io, and a Bootstrap frontend. It exposed APIs and real-time transport without authentication or TLS, including /api/beacons, /api/command, /api/results/{id}, /api/logs/{id}, /api/keylog/{id}, and /api/browser-data/{id}. Socket.io accepted unauthenticated connections and broadcast command_result events without session isolation.
Based on exposed panel JavaScript, APIs, and logs, Auraboros supports screenshot capture, webcam capture, live microphone/audio streaming, clipboard theft, keylogging, browser credential, cookie, and history theft from Chrome and Brave, Wi-Fi password extraction, file browsing and upload/download, process listing and termination, ARP discovery, port scanning, shell command execution, reverse SOCKS5 proxying, cookie-based session impersonation, OTA agent updates, and self-destruct. Browser extraction logs indicated use of Windows DPAPI to decrypt browser master keys. Event logs suggested the implant likely operated via malicious DLL sideloading rather than solely as a standalone executable.
At the time of investigation, only one beacon was registered: ID DESKTOP-FVPFLD2, user LabCasa, located in Goiânia, Brazil, on Lenovo hardware with a 12th Gen Intel Core i5-1235U. The implant process name was DiskIntegrityScanner.exe, apparently masquerading as a legitimate utility. Researchers assessed this beacon was likely the developer’s own test machine, and repeated testing activity indicated the framework was still in active development rather than broad operational deployment.
High-confidence indicators mentioned in the content include 174.138.43[.]25, ports 5000/9000/1080, the process name DiskIntegrityScanner.exe, and the beacon ID DESKTOP-FVPFLD2. No specific threat actor attribution was confirmed beyond indications of Brazilian Portuguese development context. Overall, the framework was assessed as technically capable but operationally immature, with severe OPSEC failures exposing infrastructure, telemetry, and developer testing activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Across 34 subnets announced by a 3-month-old bulletproof ASN, we found 1,004 transparent AiTM proxy servers impersonating 40+ services including GitHub, Microsoft, Apple, VK, Yandex, Yahoo, Amazon, Oracle, Tesla, Intel, Samsung, Reddit, Zoom, WhatsApp, Wikipedia, and the Linux kernel source distribution infrastructure.
Across 34 subnets announced by a 3-month-old bulletproof ASN, we found 1,004 transparent AiTM proxy servers impersonating 40+ services including GitHub, Microsoft, Apple, VK, Yandex, Yahoo, Amazon, Oracle, Tesla, Intel, Samsung, Reddit, Zoom, WhatsApp, Wikipedia, and the Linux kernel source distribution infrastructure.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Auraboros is referenced as command-and-control infrastructure via an exposed C2 panel. No further malware functionality is described in the content.
Previously undocumented command-and-control framework/implant with capabilities including screenshot capture, webcam access, live audio streaming, keylogging, browser credential and cookie theft, Wi-Fi password extraction, file browsing, ARP/port scanning, reverse SOCKS5 proxying, cookie impersonation, OTA agent updates, DLL sideloading, DPAPI-based browser credential theft, and self-destruct behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.