Skip to content

Aurora Stealer

Aurora Stealer is a Windows information-stealing malware family written in Go that emerged in 2022 and has been sold through a malware-as-a-service model on Russian-speaking criminal forums.

Profile source: Mallory opens in a new tab

Aurora Stealer

Family profile

Aurora Stealer is a Windows information-stealing malware family written in Go that emerged in 2022 and has been sold through a malware-as-a-service model on Russian-speaking criminal forums. It has been observed in financially motivated campaigns targeting organizations and individual users, including infections in the manufacturing sector, and is commonly delivered through malvertising and fake software download pages impersonating popular applications and vendors. Aurora Stealer has also been distributed through pay-per-install ecosystems and loader chains including HijackLoader, also tracked as IDAT Loader or RUGMI, and has appeared in campaigns associated with the SteelClover cluster.

Its core function is theft of sensitive data from infected systems. Aurora Stealer collects browser-stored credentials, cookies, autofill data, and other browser artifacts from Chromium-based browsers, and reporting also attributes theft of browser data from major browsers including Chrome, Edge, and Firefox in some deployment chains. It can steal cryptocurrency wallet data from numerous wallet applications, capture Telegram Desktop session data, take screenshots, and gather host profiling information such as operating system and hardware details. Later versions added theft of FTP and Remote Desktop credentials. The malware also includes grabber functionality for collecting attacker-selected files and folders.

Aurora Stealer supports additional post-compromise functionality beyond simple data theft. Builds have included an embedded loader capable of downloading and executing further payloads or launching PowerShell commands, and the broader service offering has advertised auxiliary modules for remote access, brute force, scanning, and DDoS-style botnet activity. Exfiltration is performed through structured communications with command-and-control infrastructure, with stolen data packaged and transmitted in encoded and compressed form. The malware also supports operator notifications through Telegram.

The family uses multiple evasion and deployment techniques. Reported samples use junk-byte padding, packing or crypting, and anti-analysis measures. Aurora Stealer is frequently delivered via fake installers promoted through Google Ads and other traffic acquisition methods, often masquerading as legitimate software such as text editors, remote administration tools, collaboration software, or hardware drivers. In other cases it is the final payload of multi-stage loader chains that use DLL sideloading, process injection, persistence mechanisms, and living-off-the-land execution to establish and protect execution before deploying the stealer.

Capabilities

  • Brute Force
  • Credential Theft
  • Ddos
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance
  • Scanning
  • Session Hijacking

MITRE ATT&CK

Aurora Stealer in ATT&CK

35 distinct techniques

Reporting

Research mentioning Aurora Stealer

Jul 28
Sekoia

Aurora: A Rising Stealer Flying Under the Radar

Aurora Stealer, a Golang-based information stealer sold on Russian-speaking underground forums and Telegram, has been widely distributed through fake software installers, phishing pages, cracked-software lures, and spoofed download sites impersonating tools such as Notepad++, TeamViewer, and Nvidia Driver packages. Researchers said the malware evolved from a botnet marketed as malware-as-a-service into a broadly adopted stealer used by multiple traffer teams, with infections observed against organizations including manufacturers. Aurora steals browser data, cryptocurrency wallet files and extensions, Telegram session data, screenshots, and local files, while newer variants also target FTP and RDP credentials. Aurora has also been delivered by the in2al5d p3in4er loader, a low-detection malware component compiled with Embarcadero RAD Studio that uses a GPU-based anti-VM check through dxgi.dll and CreateDXGIFactory to avoid sandbox analysis. After validating that the host uses NVIDIA, AMD, or Intel graphics, the loader decrypts and launches Aurora through process hollowing into sihost.exe or direct memory execution. Once active, Aurora fingerprints Windows hosts with WMIC, stores configuration data in base64, and exfiltrates stolen logs as compressed, base64-encoded JSON over TCP—commonly on port 8081—while also retaining loader functionality to fetch and execute additional payloads via PowerShell.

Apr 21
Morphisec

in2al5d p3in4er is Almost Completely Undetectable

Dec 18
Seqrite

BATLOADER 2.X Malware Analysis and Attack Tactics | Seqrite

Researchers linked Batloader activity to the Water Minyades / DEV-0569 / SteelClover ecosystem, which used malvertising, SEO poisoning, and fake software download pages to lure victims into installing trojanized packages. The campaigns abused legitimate installer frameworks such as Advanced Installer and WiX, then shifted to obfuscated JavaScript and PyArmor-protected Python loaders that fingerprinted hosts, contacted command-and-control infrastructure, escalated privileges, and attempted to disable security tools. Operators also used cloned software sites and malicious Google ads to distribute MSI files that launched PowerShell, added Microsoft Defender exclusions, and retrieved encrypted follow-on payloads. The infections were used to selectively deploy a broad set of malware, including Qakbot, Ursnif, Vidar, ZLoader, RedLine Stealer, Raccoon Stealer, Cobalt Strike, and remote-management tools such as Atera and Syncro. Trend Micro reported that Batloader infections observed from September 2022 onward were associated with Royal ransomware, while NTT documented a surge of related infections at Japanese companies in early 2023 through the FakeGPG and BatApp campaigns. The activity was concentrated heavily in the United States but also affected Canada, Germany, Japan, and the United Kingdom, underscoring Batloader's role as a flexible initial-access platform for both credential theft and ransomware intrusion chains.

Aug 7
Trend Micro Research

Latest Batloader Campaigns Use Pyarmor Pro for Evasion | Trend Micro (US)

Jun 15
Esentire

eSentire Threat Intelligence Malware Analysis: Aurora Stealer | eSentire

Apr 23
Openanalysis Research

in2al5dp3in4er Loader | OALABS Research

Mar 30
Esentire

eSentire Threat Intelligence Malware Analysis: BatLoader | eSentire

Mar 9
Esentire

BatLoader Continues to Abuse Google Search Ads to Deliver Vidar Stealer and Ursnif | eSentire

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.