AuraStealer has emerged as a growing malware-as-a-service infostealer operation, first advertised on Russian-language cybercrime forums and assessed to be run by Russian-speaking operators. Researchers describe it as a crude but actively developed clone of LummaC2, with subscription-based access, iterative releases through at least version 1.5.2, and a theft focus spanning browser credentials, cryptocurrency wallets, authentication tokens, and host reconnaissance data. The malware uses layered obfuscation, anti-analysis techniques, and AES-CBC to protect both embedded configuration data and communications with its command-and-control infrastructure.
Multiple campaigns have already delivered AuraStealer in the wild, including ClickFix-style TikTok lures and infections chained through malware loaders. Investigators identified 48 C2 domains, with infrastructure largely masked behind Cloudflare and an apparent migration from .shop to .cfd domains over time. Additional reverse-engineering reports highlight continued code changes and operator efforts to complicate analysis further, while the backend administration panel reportedly relies on outdated software components even as the developers signal plans to add code virtualization.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Gen Digital published a deeper technical analysis of AuraStealer and examined version 1.5.2, showing the malware was under active development months after its initial forum advertising.
The domain auracorp[.]cfd, used for the AuraStealer panel, was first registered through Web Commerce Communications Ltd. Intrinsec later observed it resolving to Cloudflare IP addresses.
The user "AuraCorp" advertised AuraStealer on the Russian-language XSS forum, marking the malware's first observed appearance on hacker forums. Intrinsec assessed the operation as being run by Russian-speaking individuals.
Foresiet published an early technical analysis of AuraStealer, documenting the malware as a crude clone of LummaC2 and helping establish early public technical visibility into the threat.
After the initial XSS post, similar AuraStealer promotional posts appeared on Exploit, Darkmarket, Blackbones, Sinister, Enclave, and Darkstash, indicating broader criminal marketing of the stealer-as-a-service offering.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 359 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
intrinsec.com
Open sourceblog.xyris.mov
Open sourceforesiet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.