logo

Auraboros RAT Adds Live Audio, Keylogging, and Cookie Theft via Open C2 Panel

ID: 0b4c851b-9a9b-546d-9662-b06e4625cfe3

STIX ID: report--0b4c851b-9a9b-546d-9662-b06e4625cfe3

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A security researcher discovered an unauthenticated Auraboros RAT command-and-control panel exposed at http://174.138.43.25:5000 that actively displays victim beacons and accepts live commands; the malware supports live audio streaming, intensive keylogging, browser credential and cookie theft, reverse SOCKS5 tunneling for session replay, and DLL sideloading-based implants. All APIs and Socket.io channels are served over plaintext HTTP with CORS set to *, allowing anyone to view victim data and command results in real time; the instance observed appears to be a developer’s home-lab beacon hosted on a DigitalOcean VPS, indicating the framework is high-risk but currently at limited scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.