Skip to content
Malware family

Aurora Stealer

Aurora Stealer is an infostealer delivered in the observed case as the final payload of the RUGMI/HijackLoader malware ecosystem, also tracked as IDAT Loader, a malware-as-a-service/pay-per-install loader active since 2023.

Profile source: Mallory opens in a new tab

Aurora Stealer

Family profile

Aurora Stealer is an infostealer delivered in the observed case as the final payload of the RUGMI/HijackLoader malware ecosystem, also tracked as IDAT Loader, a malware-as-a-service/pay-per-install loader active since 2023. In the analyzed chain, a fully decrypted Stage 4 payload used aggressive DLL sideloading with legitimate signed binaries including Sysinternals tcpvcon.exe and a jpegoptim-themed launcher (EngineX-Aurora.exe disguised as jpegoptim.exe), DLL search order hijacking via malicious pla.dll and d3d9.dll/Register.dll, Living-off-the-Land execution through MSBuild.exe, process injection into explorer.exe, persistence via %LOCALAPPDATA%\RaScope.exe and the Windows Startup folder, and reportedly included modules for UAC bypass and scheduled task creation. The Aurora payload is assessed to steal browser credentials from Chrome, Firefox, and Edge, harvest cookies and session tokens, steal cryptocurrency wallets, and exfiltrate files. Its command-and-control configuration was stored in a high-entropy encrypted blob and could not be statically recovered without the runtime decryption key, indicating encrypted C2 communications. The analyzed sample contained campaign identifier xy_Alt_betav1 and a PDB path in EngineX-Aurora.exe exposing the username xmr. Reported artifacts from this deployment include stage_4_decrypted_payload.bin (SHA256 c89f99602d833822c0954ac0266580919816da23b2adeb820dcf8b5639afb04a), tcpvcon.exe (SHA256 e202f137869cce7fdea6b6cd1169f5e0b6a46cc2d89265a31f63484b0f48bb29), tinystub64.bin/Register.dll (SHA256 729e5965e43ff458f6da901536c9a43be52a3820718e2dd5456150e2d73bb97f), and EngineX-Aurora.exe (SHA256 c52664283a0dc2c3d500b236ce2d5379802c0d74d903da6b3e133b2de6e77949). Related IDAT Loader campaigns have targeted Ukrainian organizations. Separately, Spamhaus researchers linked fake Nvidia lookalike domains used in Google Ad malvertising to Aurora Stealer and Vidar, indicating malvertising as an additional observed delivery vector.

MITRE ATT&CK

Aurora Stealer in ATT&CK

17 distinct techniques

Reporting

Research mentioning Aurora Stealer

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.