Skip to content

AuraStealer

AuraStealer is a Windows malware-as-a-service infostealer that emerged in mid-2025 and has been advertised on multiple underground forums by operators assessed to be Russian-speaking.

Profile source: Mallory opens in a new tab

AuraStealer

Family profile

AuraStealer is a Windows malware-as-a-service infostealer that emerged in mid-2025 and has been advertised on multiple underground forums by operators assessed to be Russian-speaking. It is sold through subscription tiers and supported by a web-based management panel for campaign administration and stolen-data review, indicating an organized commercialized criminal operation under active development.

AuraStealer is designed to steal a broad range of victim data, including browser credentials, cookies and session tokens, cryptocurrency wallet material, two-factor authentication data, recovery seeds, API keys, VPN configurations, clipboard contents, screenshots, and general host and process information. It also targets password managers and data from numerous browsers, applications, and browser extensions. The malware can retrieve additional collection directives from command-and-control infrastructure and can execute follow-on payloads, extending its utility beyond simple credential theft.

Technically, AuraStealer employs substantial anti-analysis and defense-evasion measures. Reported protections include indirect control-flow obfuscation, string obfuscation, exception-driven API hashing, anti-debugging, anti-virtual-machine and anti-sandbox checks, anti-tamper logic, and geofencing that prevents execution in parts of the former Soviet Union. It stores embedded configuration data in AES-CBC-encrypted form and also protects command-and-control traffic with AES-CBC. AuraStealer has also been observed bypassing Chromium Application-Bound Encryption by injecting code into a browser context to recover protected keys, enabling theft of browser secrets that newer Chromium protections were intended to harden.

Observed delivery has relied heavily on social engineering. AuraStealer has been distributed in ClickFix-style and broader “Scam-Yourself” campaigns, especially through TikTok videos masquerading as software activation or installation tutorials that trick users into executing malicious PowerShell commands themselves. Additional observed distribution methods include cracked software, self-extracting archives, Visual Basic script chains, malicious loaders, Donut-based shellcode delivery, DLL sideloading, and process injection into legitimate Windows binaries.

AuraStealer targets Windows systems, with reporting indicating compatibility from Windows 7 through Windows 11. Its combination of broad data-theft coverage, active development, layered obfuscation, MaaS commercialization, and flexible delivery through social-engineering and loader ecosystems makes it a notable contemporary infostealer threat.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Post Exploitation
  • Process Injection
  • Session Hijacking

Observed infrastructure

Last seven days

First activity
Aug 28, 2026
Last activity
Aug 28, 2026
Feed role
C2
Host form
0 IP / 4 hostnames

Samples

Recent associated samples

MITRE ATT&CK

AuraStealer in ATT&CK

42 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.