logo

Aurora: A rising stealer flying under the radar

ID: cbc57993-afa0-50ba-8269-d5cb056caeef

STIX ID: report--cbc57993-afa0-50ba-8269-d5cb056caeef

Feed Name: Sekoia.com

Threat Score
75/100

Date Published: 2022-11-21

Date Updated: 2026-07-20

...
...

## Executive summary Sekoia analysed Aurora, a Golang infostealer first marketed as a botnet, now widely distributed by multiple trafficker teams: it collects browser data, cryptocurrency wallet information, system fingerprints (via WMIC), captures screenshots, exfiltrates JSON-formatted data over TCP to C2 servers (commonly on port 8081), and can download and execute a next-stage payload; the report includes infection-chain examples, numerous IoCs (C2 IPs, file hashes, malicious URLs), a YARA rule, and ATT&CK mappings, concluding Aurora is a growing and actively used threat in cybercriminal ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.