New Auraboros RAT Exposes Live Audio Streaming, Keylogging, and Cookie Hijacking in Open C2 Panel
ID: 89be4dda-bb1b-5a30-89c3-0341f9c603d5
STIX ID: report--89be4dda-bb1b-5a30-89c3-0341f9c603d5
Feed Name: cybersecurityNews.com
This report details a newly discovered remote access trojan framework called Auraboros C2 whose unauthenticated Express.js/Socket.io dashboard (hosted at 174.138.43.25:5000) freely exposes victim data and real-time logs. The implant uses DLL sideloading via DiskIntegrityScanner.exe, harvests Windows DPAPI-protected browser credentials (Brave/Chrome), supports live keylogging, webcam/screenshot capture, SOCKS5 proxying (port 1080) and cookie impersonation; investigators found the full JavaScript source and a single developer test beacon. Immediate guidance includes blocking 174.138.43.25, hunting for DiskIntegrityScanner.exe, monitoring DigitalOcean-hosted outbound connections to port 9000, alerting on SOCKS5 activity on 1080, and reporting the infrastructure to DigitalOcean.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
