logo

Threat Actors Deploy ‘AuraStealer’ Infostealer with 48 C2 Domains and Active Campaigns

ID: 3d6102a1-e472-5480-8fc2-2e0a6fcf82c5

STIX ID: report--3d6102a1-e472-5480-8fc2-2e0a6fcf82c5

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

AuraStealer is a Russian-speaking actor-developed information-stealing malware first advertised in mid-2025, positioned as a commercial stealer with subscription pricing, a management panel, and Telegram integration. Analysts found over 200 samples and 48 linked C2 domains (using .SHOP and .CFD TLDs routed through Cloudflare); it harvests browser credentials, crypto wallets, 2FA tokens, session cookies, VPN configs, password manager databases and more. Distribution uses social-engineering 'ClickFix' lures (notably malicious TikTok videos instructing users to run PowerShell), various loaders, DLL sideloading, process injection, and fake tools. The report documents active campaigns, evolving infrastructure, and provides mitigation recommendations including blocking known C2 domains, restricting PowerShell/admin access, application allow-listing, endpoint detection for injection, and user awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.