Aurora Stealer, a Golang-based information stealer sold on Russian-speaking underground forums and Telegram, has been widely distributed through fake software installers, phishing pages, cracked-software lures, and spoofed download sites impersonating tools such as Notepad++, TeamViewer, and Nvidia Driver packages. Researchers said the malware evolved from a botnet marketed as malware-as-a-service into a broadly adopted stealer used by multiple traffer teams, with infections observed against organizations including manufacturers. Aurora steals browser data, cryptocurrency wallet files and extensions, Telegram session data, screenshots, and local files, while newer variants also target FTP and RDP credentials.
Aurora has also been delivered by the in2al5d p3in4er loader, a low-detection malware component compiled with Embarcadero RAD Studio that uses a GPU-based anti-VM check through dxgi.dll and CreateDXGIFactory to avoid sandbox analysis. After validating that the host uses NVIDIA, AMD, or Intel graphics, the loader decrypts and launches Aurora through process hollowing into sihost.exe or direct memory execution. Once active, Aurora fingerprints Windows hosts with WMIC, stores configuration data in base64, and exfiltrates stolen logs as compressed, base64-encoded JSON over TCP—commonly on port 8081—while also retaining loader functionality to fetch and execute additional payloads via PowerShell.

Pull IOCs and campaign context straight into your stack.
11 events from the most recent confirmed update back to the earliest known activity.
In April 2023, Morphisec publicly exposed the in2al5dp3in4er, or Invalid Printer, loader. The loader was described as using graphics-card-based sandbox evasion and delivering Aurora Stealer as its second-stage payload.
A March 2023 update to Aurora added capabilities including FTP and RDP credential theft and configurable ports for panel and command-and-control communications. This represented a functional expansion of the stealer.
Morphisec reported that Aurora became a popular Golang-based information stealer from late 2022 through the first quarter of 2023. The malware was delivered in campaigns using compromised YouTube accounts and fake download websites.
eSentire's Threat Response Unit observed Aurora Stealer infections affecting manufacturing organizations starting in December 2022. The infections were linked to fake Google Ads and spoofed software installers such as Notepad++, TeamViewer, and Nvidia Driver pages.
In October and November 2022, Sekoia observed several hundred Aurora samples and dozens of active command-and-control servers. This reflected a significant increase in operational scale after the malware's repositioning as a stealer.
By late August and September 2022, multiple traffers teams publicly announced that they had added Aurora to their infostealer arsenals. Sekoia identified nine such teams, indicating broader criminal adoption.
In late August 2022, Aurora was re-advertised on Telegram and underground forums as a stealer rather than a botnet service. This marked a shift in how the malware was positioned and sold to criminal users.
Sekoia observed Aurora server activity largely stop in late July 2022, with newer samples no longer appearing in a public repository. The report assessed that MaaS development may have been abandoned after the developer stopped posting in June 2022.
In July 2022, Sekoia discovered Aurora as a new Golang botnet and identified around 50 related samples, most tied to the Cheshire and Zelizzard botnets. It also observed fewer than a dozen associated command-and-control servers at that time.
Aurora was first advertised in April 2022 by a threat actor using the handle Cheshire as a multi-purpose botnet sold as Malware-as-a-Service. Early sales pitches included stealing, downloading, and remote access capabilities.
By late 2022, Aurora was being distributed through several infection chains, including phishing pages impersonating legitimate software, YouTube-led cracked software lures, and fake software catalog websites. Sekoia assessed that several threat actors were distributing Aurora using different delivery techniques.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 117 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
blog.sekoia.io
Open sourceblog.morphisec.com
Open sourceesentire.com
Open sourceresearch.openanalysis.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.