Aurora Stealer
Aurora Stealer is an infostealer delivered in the observed case as the final payload of the RUGMI/HijackLoader malware ecosystem, also tracked as IDAT Loader, a malware-as-a-service/pay-per-install loader active since 2023.
Profile source: Mallory opens in a new tabAurora Stealer
Family profile
Aurora Stealer is an infostealer delivered in the observed case as the final payload of the RUGMI/HijackLoader malware ecosystem, also tracked as IDAT Loader, a malware-as-a-service/pay-per-install loader active since 2023. In the analyzed chain, a fully decrypted Stage 4 payload used aggressive DLL sideloading with legitimate signed binaries including Sysinternals tcpvcon.exe and a jpegoptim-themed launcher (EngineX-Aurora.exe disguised as jpegoptim.exe), DLL search order hijacking via malicious pla.dll and d3d9.dll/Register.dll, Living-off-the-Land execution through MSBuild.exe, process injection into explorer.exe, persistence via %LOCALAPPDATA%\RaScope.exe and the Windows Startup folder, and reportedly included modules for UAC bypass and scheduled task creation. The Aurora payload is assessed to steal browser credentials from Chrome, Firefox, and Edge, harvest cookies and session tokens, steal cryptocurrency wallets, and exfiltrate files. Its command-and-control configuration was stored in a high-entropy encrypted blob and could not be statically recovered without the runtime decryption key, indicating encrypted C2 communications. The analyzed sample contained campaign identifier xy_Alt_betav1 and a PDB path in EngineX-Aurora.exe exposing the username xmr. Reported artifacts from this deployment include stage_4_decrypted_payload.bin (SHA256 c89f99602d833822c0954ac0266580919816da23b2adeb820dcf8b5639afb04a), tcpvcon.exe (SHA256 e202f137869cce7fdea6b6cd1169f5e0b6a46cc2d89265a31f63484b0f48bb29), tinystub64.bin/Register.dll (SHA256 729e5965e43ff458f6da901536c9a43be52a3820718e2dd5456150e2d73bb97f), and EngineX-Aurora.exe (SHA256 c52664283a0dc2c3d500b236ce2d5379802c0d74d903da6b3e133b2de6e77949). Related IDAT Loader campaigns have targeted Ukrainian organizations. Separately, Spamhaus researchers linked fake Nvidia lookalike domains used in Google Ad malvertising to Aurora Stealer and Vidar, indicating malvertising as an additional observed delivery vector.
MITRE ATT&CK
Aurora Stealer in ATT&CK
17 distinct techniquesReporting
Research mentioning Aurora Stealer
RUGMI/IDAT Loader + Aurora Stealer - Multi-Stage DLL Sideloading Campaign - Breakglass Intelligence - Breakglass Intelligence
This sample is a fully decrypted Stage 4 payload from the RUGMI/HijackLoader (also tracked as IDAT Loader) pay-per-install malware ecosystem, delivering an Aurora Stealer infostealer as the final payload.
A surge of malvertising across Google Ads is distributing dangerous malware
Spamhaus researchers have linked fake Nvidia domains with Aurora Stealer and Vidar malware.