Skip to content

Aurora

Aurora is a ransomware operation tracked by ransomware.live.

Profile source: Ransomware.live opens in a new tab

Aurora

Family profile

Aurora is a ransomware operation tracked by ransomware.live. It is a separate family from the credential-stealing malware tracked as Aurora Stealer.

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
1 available

Recent claims

Reporting

Research mentioning Aurora

Jul 28
Sekoia

Aurora: A Rising Stealer Flying Under the Radar

Aurora Stealer, a Golang-based information stealer sold on Russian-speaking underground forums and Telegram, has been widely distributed through fake software installers, phishing pages, cracked-software lures, and spoofed download sites impersonating tools such as Notepad++, TeamViewer, and Nvidia Driver packages. Researchers said the malware evolved from a botnet marketed as malware-as-a-service into a broadly adopted stealer used by multiple traffer teams, with infections observed against organizations including manufacturers. Aurora steals browser data, cryptocurrency wallet files and extensions, Telegram session data, screenshots, and local files, while newer variants also target FTP and RDP credentials. Aurora has also been delivered by the in2al5d p3in4er loader, a low-detection malware component compiled with Embarcadero RAD Studio that uses a GPU-based anti-VM check through dxgi.dll and CreateDXGIFactory to avoid sandbox analysis. After validating that the host uses NVIDIA, AMD, or Intel graphics, the loader decrypts and launches Aurora through process hollowing into sihost.exe or direct memory execution. Once active, Aurora fingerprints Windows hosts with WMIC, stores configuration data in base64, and exfiltrates stolen logs as compressed, base64-encoded JSON over TCP—commonly on port 8081—while also retaining loader functionality to fetch and execute additional payloads via PowerShell.

Apr 21
Morphisec

in2al5d p3in4er is Almost Completely Undetectable

Dec 18
Seqrite

BATLOADER 2.X Malware Analysis and Attack Tactics | Seqrite

Researchers linked Batloader activity to the Water Minyades / DEV-0569 / SteelClover ecosystem, which used malvertising, SEO poisoning, and fake software download pages to lure victims into installing trojanized packages. The campaigns abused legitimate installer frameworks such as Advanced Installer and WiX, then shifted to obfuscated JavaScript and PyArmor-protected Python loaders that fingerprinted hosts, contacted command-and-control infrastructure, escalated privileges, and attempted to disable security tools. Operators also used cloned software sites and malicious Google ads to distribute MSI files that launched PowerShell, added Microsoft Defender exclusions, and retrieved encrypted follow-on payloads. The infections were used to selectively deploy a broad set of malware, including Qakbot, Ursnif, Vidar, ZLoader, RedLine Stealer, Raccoon Stealer, Cobalt Strike, and remote-management tools such as Atera and Syncro. Trend Micro reported that Batloader infections observed from September 2022 onward were associated with Royal ransomware, while NTT documented a surge of related infections at Japanese companies in early 2023 through the FakeGPG and BatApp campaigns. The activity was concentrated heavily in the United States but also affected Canada, Germany, Japan, and the United Kingdom, underscoring Batloader's role as a flexible initial-access platform for both credential theft and ransomware intrusion chains.

Aug 7
Trend Micro Research

Latest Batloader Campaigns Use Pyarmor Pro for Evasion | Trend Micro (US)

Jun 15
Esentire

eSentire Threat Intelligence Malware Analysis: Aurora Stealer | eSentire

Apr 23
Openanalysis Research

in2al5dp3in4er Loader | OALABS Research

Mar 30
Esentire

eSentire Threat Intelligence Malware Analysis: BatLoader | eSentire

Mar 9
Esentire

BatLoader Continues to Abuse Google Search Ads to Deliver Vidar Stealer and Ursnif | eSentire

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.