Open C2 Panel Reveals Auraboros RAT Audio Streaming and Keylogging Features
ID: 624b183e-68cd-54c5-8c65-131753c01e26
STIX ID: report--624b183e-68cd-54c5-8c65-131753c01e26
Feed Name: Cyber Press
Cybersecurity researchers discovered 'Auraboros C2', a previously undocumented command-and-control framework and accompanying Windows remote access trojan that performs live audio and webcam streaming, keystroke logging, browser credential/cookie theft (via DPAPI decryption), and session hijacking through a reverse SOCKS5 proxy. The implant uses DLL sideloading and maintains persistent Socket.io connections; however, the C2 dashboard and APIs are exposed over plain HTTP without authentication or session isolation, providing wide-open access to stolen data and operational controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
