logo

Open C2 Panel Reveals Auraboros RAT Audio Streaming and Keylogging Features

ID: 624b183e-68cd-54c5-8c65-131753c01e26

STIX ID: report--624b183e-68cd-54c5-8c65-131753c01e26

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Varshini

...
...

Cybersecurity researchers discovered 'Auraboros C2', a previously undocumented command-and-control framework and accompanying Windows remote access trojan that performs live audio and webcam streaming, keystroke logging, browser credential/cookie theft (via DPAPI decryption), and session hijacking through a reverse SOCKS5 proxy. The implant uses DLL sideloading and maintains persistent Socket.io connections; however, the C2 dashboard and APIs are exposed over plain HTTP without authentication or session isolation, providing wide-open access to stolen data and operational controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.