Aurora Stealer
Aurora Stealer is a Windows information-stealing malware family written in Go that emerged in 2022 and has been marketed as a malware-as-a-service offering on Russian-speaking criminal forums.
Profile source: Mallory opens in a new tabAurora Stealer
Family profile
Aurora Stealer is a Windows information-stealing malware family written in Go that emerged in 2022 and has been marketed as a malware-as-a-service offering on Russian-speaking criminal forums. It has been associated with financially motivated cybercrime activity and is commonly delivered through malvertising and fake software download pages impersonating popular applications and vendors. Observed delivery chains have included spoofed installer pages promoted through Google Ads, pay-per-install ecosystems such as HijackLoader/IDAT Loader, and other loader-based distribution arrangements.
Aurora Stealer focuses on collecting sensitive user and host data. Core functionality includes theft of browser credentials, cookies, autofill data, and other stored browser artifacts; collection of cryptocurrency wallet data from numerous wallet applications; theft of Telegram Desktop session data; screenshot capture; and host profiling through system reconnaissance. Reported updates expanded credential theft to include FTP and RDP data. The malware can also archive attacker-selected files through a grabber component and supports exfiltration of stolen data to operator-controlled infrastructure using structured, compressed, and encoded communications.
Aurora Stealer includes modular post-compromise functionality beyond pure information theft. Documented builds contain a loader component capable of downloading and executing additional payloads or launching PowerShell commands, enabling follow-on malware deployment and broader post-exploitation activity. Public reporting has also described Aurora ecosystem offerings that advertised auxiliary modules such as remote access, brute-force, scanning, and DDoS capabilities, although the stealer payload itself is primarily characterized by credential and data theft.
The malware employs multiple evasion measures, including packing or crypting options, junk-byte padding, runtime configuration storage in encoded form, and temporary staging of stolen data before exfiltration. In some delivery chains, Aurora has been deployed through multi-stage loaders that use DLL sideloading, process injection, persistence mechanisms, and anti-analysis checks before launching the final stealer payload.
Victimology has included manufacturing organizations and users seeking common software downloads, with campaigns observed across fake pages themed around developer tools, remote administration software, communications software, and hardware drivers. Aurora Stealer is part of the broader commodity infostealer ecosystem and is frequently used in opportunistic, financially motivated intrusion activity.
Capabilities
- Brute Force
- Credential Theft
- Ddos
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Persistence
- Post Exploitation
- Process Injection
- Reconnaissance
- Scanning
- Session Hijacking
MITRE ATT&CK
Aurora Stealer in ATT&CK
36 distinct techniquesReporting
Research mentioning Aurora Stealer
Aurora: A Rising Stealer Flying Under the Radar
Aurora Stealer, a Golang-based information stealer sold on Russian-speaking underground forums and Telegram, has been widely distributed through fake software installers, phishing pages, cracked-software lures, and spoofed download sites impersonating tools such as Notepad++, TeamViewer, and Nvidia Driver packages. Researchers said the malware evolved from a botnet marketed as malware-as-a-service into a broadly adopted stealer used by multiple traffer teams, with infections observed against organizations including manufacturers. Aurora steals browser data, cryptocurrency wallet files and extensions, Telegram session data, screenshots, and local files, while newer variants also target FTP and RDP credentials. Aurora has also been delivered by the in2al5d p3in4er loader, a low-detection malware component compiled with Embarcadero RAD Studio that uses a GPU-based anti-VM check through dxgi.dll and CreateDXGIFactory to avoid sandbox analysis. After validating that the host uses NVIDIA, AMD, or Intel graphics, the loader decrypts and launches Aurora through process hollowing into sihost.exe or direct memory execution. Once active, Aurora fingerprints Windows hosts with WMIC, stores configuration data in base64, and exfiltrates stolen logs as compressed, base64-encoded JSON over TCP—commonly on port 8081—while also retaining loader functionality to fetch and execute additional payloads via PowerShell.
in2al5d p3in4er is Almost Completely Undetectable
BATLOADER 2.X Malware Analysis and Attack Tactics | Seqrite
Researchers linked Batloader activity to the Water Minyades / DEV-0569 / SteelClover ecosystem, which used malvertising, SEO poisoning, and fake software download pages to lure victims into installing trojanized packages. The campaigns abused legitimate installer frameworks such as Advanced Installer and WiX, then shifted to obfuscated JavaScript and PyArmor-protected Python loaders that fingerprinted hosts, contacted command-and-control infrastructure, escalated privileges, and attempted to disable security tools. Operators also used cloned software sites and malicious Google ads to distribute MSI files that launched PowerShell, added Microsoft Defender exclusions, and retrieved encrypted follow-on payloads. The infections were used to selectively deploy a broad set of malware, including Qakbot, Ursnif, Vidar, ZLoader, RedLine Stealer, Raccoon Stealer, Cobalt Strike, and remote-management tools such as Atera and Syncro. Trend Micro reported that Batloader infections observed from September 2022 onward were associated with Royal ransomware, while NTT documented a surge of related infections at Japanese companies in early 2023 through the FakeGPG and BatApp campaigns. The activity was concentrated heavily in the United States but also affected Canada, Germany, Japan, and the United Kingdom, underscoring Batloader's role as a flexible initial-access platform for both credential theft and ransomware intrusion chains.