Aurora: A rising stealer flying under the radar
ID: cbc57993-afa0-50ba-8269-d5cb056caeef
STIX ID: report--cbc57993-afa0-50ba-8269-d5cb056caeef
Feed Name: Sekoia.com
## Executive summary Sekoia analysed Aurora, a Golang infostealer first marketed as a botnet, now widely distributed by multiple trafficker teams: it collects browser data, cryptocurrency wallet information, system fingerprints (via WMIC), captures screenshots, exfiltrates JSON-formatted data over TCP to C2 servers (commonly on port 8081), and can download and execute a next-stage payload; the report includes infection-chain examples, numerous IoCs (C2 IPs, file hashes, malicious URLs), a YARA rule, and ATT&CK mappings, concluding Aurora is a growing and actively used threat in cybercriminal ecosystems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
