Researchers uncovered Auraboros C2, a previously undocumented Brazilian remote access trojan framework whose management panel at 174.138.43[.]25:5000 was exposed on the public internet without authentication. The HTTP-based Express.js and Socket.io dashboard, hosted on DigitalOcean and written in Brazilian Portuguese, allowed anyone with network access to view victim metadata, command history, keylogs, browser credential theft results, and real-time operator activity. Investigators said the platform supports extensive surveillance and post-compromise actions, including screenshots, webcam capture, live audio streaming, Wi-Fi password extraction, file operations, shell execution, reverse SOCKS5 proxying, and over-the-air malware updates.
Analysis indicated the Windows implant likely used DLL sideloading via DiskIntegrityScanner.exe, decrypted Chrome and Brave credentials with Windows DPAPI, and included a cookie impersonation capability alongside a self-destruct function. Despite the broad feature set, researchers found only one registered beacon tied to a Lenovo laptop in Goiânia, Brazil, suggesting the infrastructure was still in development or testing rather than large-scale deployment. The exposed server also listened on ports 1080 and 9000, believed to support reverse SOCKS5 and beacon or stager traffic, and the operator was assessed as a Brazilian Portuguese-speaking developer whose poor operational security left the entire framework and test telemetry publicly accessible.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Censys disclosed technical details on the long-running OLUOMO phishing cluster, including its two-stage architecture, use of a stolen naturalization-form lure image, service worker registration, and routing through the lookalike domain orgid[.]com. The report also described geographically distributed first-stage infrastructure and Azure-hosted second-stage backends.
Breakglass Intelligence published a report detailing Auraboros C2's capabilities, including keylogging, browser credential theft, live audio streaming, webcam capture, reverse SOCKS5 proxying, and OTA updates. The report assessed the infrastructure as likely still in development, with only one beacon tied to a Lenovo laptop in Goiânia, Brazil.
Breakglass Intelligence, after receiving tips from external researchers, identified a previously undocumented Brazilian RAT framework called Auraboros C2 exposed on 174.138.43[.]25. Its HTTP management panel on port 5000 was accessible without authentication and exposed victim data, commands, and operator functionality.
Ctrl-Alt-Intel published research on the UPMI phishing-as-a-service platform. The reference indicates public reporting on the phishing operation by this date, though the synopsis provides no further event details.
Censys reported that the adversary-in-the-middle phishing cluster it tracks as OLUOMO has been active since late November 2025, targeting Microsoft credentials and session tokens. The campaign used compromised legitimate websites as first-stage lures and Azure Web Apps as second-stage phishing proxies.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 60 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
censys.com
Open sourcecybersecuritynews.com
Open sourceintel.breakglass.tech
Open sourcectrlaltintel.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.