Aurora
Aurora is a ransomware operation tracked by ransomware.live.
Profile source: Ransomware.live opens in a new tabAurora
Family profile
Aurora is a ransomware operation tracked by ransomware.live. It is a separate family from the credential-stealing malware tracked as Aurora Stealer.
Operational record
Recent claims
Reporting
Research mentioning Aurora
Aurora: A Rising Stealer Flying Under the Radar
Aurora Stealer, a Golang-based information stealer sold on Russian-speaking underground forums and Telegram, has been widely distributed through fake software installers, phishing pages, cracked-software lures, and spoofed download sites impersonating tools such as Notepad++, TeamViewer, and Nvidia Driver packages. Researchers said the malware evolved from a botnet marketed as malware-as-a-service into a broadly adopted stealer used by multiple traffer teams, with infections observed against organizations including manufacturers. Aurora steals browser data, cryptocurrency wallet files and extensions, Telegram session data, screenshots, and local files, while newer variants also target FTP and RDP credentials. Aurora has also been delivered by the in2al5d p3in4er loader, a low-detection malware component compiled with Embarcadero RAD Studio that uses a GPU-based anti-VM check through dxgi.dll and CreateDXGIFactory to avoid sandbox analysis. After validating that the host uses NVIDIA, AMD, or Intel graphics, the loader decrypts and launches Aurora through process hollowing into sihost.exe or direct memory execution. Once active, Aurora fingerprints Windows hosts with WMIC, stores configuration data in base64, and exfiltrates stolen logs as compressed, base64-encoded JSON over TCP—commonly on port 8081—while also retaining loader functionality to fetch and execute additional payloads via PowerShell.
in2al5d p3in4er is Almost Completely Undetectable
BATLOADER 2.X Malware Analysis and Attack Tactics | Seqrite
Researchers linked Batloader activity to the Water Minyades / DEV-0569 / SteelClover ecosystem, which used malvertising, SEO poisoning, and fake software download pages to lure victims into installing trojanized packages. The campaigns abused legitimate installer frameworks such as Advanced Installer and WiX, then shifted to obfuscated JavaScript and PyArmor-protected Python loaders that fingerprinted hosts, contacted command-and-control infrastructure, escalated privileges, and attempted to disable security tools. Operators also used cloned software sites and malicious Google ads to distribute MSI files that launched PowerShell, added Microsoft Defender exclusions, and retrieved encrypted follow-on payloads. The infections were used to selectively deploy a broad set of malware, including Qakbot, Ursnif, Vidar, ZLoader, RedLine Stealer, Raccoon Stealer, Cobalt Strike, and remote-management tools such as Atera and Syncro. Trend Micro reported that Batloader infections observed from September 2022 onward were associated with Royal ransomware, while NTT documented a surge of related infections at Japanese companies in early 2023 through the FakeGPG and BatApp campaigns. The activity was concentrated heavily in the United States but also affected Canada, Germany, Japan, and the United Kingdom, underscoring Batloader's role as a flexible initial-access platform for both credential theft and ransomware intrusion chains.