The Aur0ra/Aurora Locker ransomware operation has been linked to double-extortion attacks beginning with email bombing and vishing calls impersonating IT helpdesks. In one investigated intrusion, operators used renamed Xray-core binaries as reverse command-and-control tunnels, configured with VLESS/REALITY traffic masquerading as Chrome connections to dl.google.com; they then moved laterally, obtained privileged administrative access, cleared logs, weakened Microsoft Defender, and timestomped the tunnel binaries. The attackers deleted shadow copies, deployed a victim-specific locker and dist.exe distributor, and left !!!README!!!DO_NOT_DELETE.txt notes; encrypted files retained their original names and extensions but received a footer containing magic bytes 66 18 a7 2f.
Reporting indicates Aurora affiliates conduct the full attack lifecycle rather than solely brokering initial access, including credential theft, Active Directory compromise, data exfiltration, encryptor staging, extortion, and payment collection. Blockchain tracing identified two confirmed ransom payments and two more consistent with victim payments, routed through shared laundering and consolidation infrastructure before cash-out. The affiliate is assessed as Russian-speaking and opportunistically targets organizations outside the CIS; compensation appears individually negotiated rather than governed by a fixed ransomware-as-a-service split. On ESXi/Linux systems, Aurora has also modified the SSH banner configuration to display ransom demands instead of dropping a conventional ransom-note file.

TTPs, infrastructure, and targeting history in one profile.
17 events from the most recent confirmed update back to the earliest known activity.
On August 18, 2026, BHIS ActiveSOC published an incident report describing Aur0ra's locker as encrypting files in place without renaming them or adding extensions; encrypted files contained magic value 6618a72f and an RSA-wrapped per-file key. The report also documented ESXi/Hyper-V support, configurable partial encryption and multithreading, plus associated IP addresses and SHA-256 indicators.
From April 8 through May 26, 2026, Aurora operators used Cursor Agent running Claude Sonnet against 10 victims after supplying credentials or an existing access route. They tasked the agent with Active Directory and subnet enumeration, NTLM relay and certificate-service attacks, and VPN or proxy configuration; commands often required iterative refinement, with some tasks ultimately succeeding.
From April through July 2026, a Russian-speaking Aurora affiliate targeted more than 20 organizations across nine countries, obtaining domain-level or interactive access at 17 targets; four victims appeared on Aurora's leak site. An exposed server containing intrusion tooling, credentials, negotiation data, and Russian-language Cursor AI chat records supported CloudSEK's assessment that the operator was an active ransomware affiliate rather than an access broker.
Aur0ra reportedly emerged as a double-extortion ransomware group in late April 2026.
Aurora's Linux encrypt.out ransomware supports an ESXi mode that identifies running virtual machines, forcibly terminates them to release virtual-disk locks, and encrypts VM files including VMDK and VMX data. It skips the BOOTBANK and OSDATA volumes, leaving the ESXi hypervisor bootable after encryption.
A separate Aurora activity cluster used SQL Server xp_cmdshell for execution, GodPotato for privilege escalation, and DCSync to obtain Active Directory credential material. The cluster also exfiltrated data through S3-based infrastructure before ransomware deployment.
Aurora-associated activity modified /etc/ssh/sshd_config to point to an sshd-banner file containing the ransom message, then restarted SSH so the message appeared during login attempts rather than being delivered as a conventional ransom-note file.
CloudSEK and TRM Labs identified two confirmed Aurora victim payments and two additional transactions consistent with payments from separate victims. The transactions used shared laundering infrastructure and varied initial payment splits, suggesting affiliate compensation may be negotiated per victim.
CloudSEK reported recovering an Aurora encryptor key that enabled access to a concluded, unnamed victim negotiation; the negotiation ended in a ransom settlement. CloudSEK and TRM Labs traced the payment on-chain.
The attackers copied ransomware components to a public Music directory, created a target list, and used dist.exe to distribute malware to shares. They executed a victim-specific locker, deleted volume shadow copies, and left !!!README!!!DO_NOT_DELETE.txt ransom notes.
The attackers altered the created, modified, and accessed timestamps of their Xray tunnel binaries to 2026-01-01 to hinder forensic analysis.
After obtaining elevated privileges, the attackers cleared hundreds of Windows event-log channels and verified the clearing with wevtutil queries. Before detonation, they also disabled multiple Microsoft Defender protections, including tamper protection and real-time monitoring.
The operators unsuccessfully tried to add an account to Domain Admins and modified an existing drive-mapping GPO to create a DriveMap-PolicyVerify scheduled task that reset a high-value domain account password. Despite those failed reset attempts, they later gained control of a high-privilege administrator account.
Affected workstations generated roughly 10,000 outbound connections each over SMB, LDAP, WinRM, RDP, and RPC as the attackers moved laterally; the Xray C2 tunnel carried WinRM sessions.
The attackers persisted the Xray tunnel through scheduled tasks named GoogleChromeUpdateCore and ConnectivityServiceAgent, as well as an HKCU Run value that launched updater.ps1 to relaunch the tunnel.
The attackers used renamed legitimate Xray-core binaries as a reverse command-and-control tunnel, configured with VLESS/REALITY and a Chrome TLS fingerprint while masquerading as Chrome update software. BHIS assessed this as Aur0ra's first documented use of Xray-core for command and control.
During an incident investigated by BHIS, attackers flooded users with emails—some receiving more than 900 messages—then impersonated an IT helpdesk by phone to gain control of victim machines.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 37 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourceinfosecurity-magazine.com
Open sourcecybersecuritynews.com
Open sourcegambit.security
Open sourcecloudsek.com
Open sourcecyberveille.ch
Open sourceactivesoc.blackhillsinfosec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.