logo

Aurora Stealer: A Shapeshifting Malware Using Evolving Tactics

ID: 0fdb54b4-5b1c-5f42-9c29-1211ae866451

STIX ID: report--0fdb54b4-5b1c-5f42-9c29-1211ae866451

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-11-13

Date Updated: 2026-07-16

...
...

This report documents a phishing-driven campaign delivering Aurora Stealer — a Go-based information stealer that impersonates messenger and TeamViewer sites to trick users into downloading padded malicious binaries (examples: messenger.exe, teamviewer.exe). The analysis provides sample hashes, download URLs, the C2 45.15.156.210:8081, detailed collection/exfiltration behavior targeting browsers, crypto wallets and extensions, discovery and evasion techniques, a list of IOCs, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.