Skip to content

Infostealer

Aura Stealer

aka AURA Stealer · AURASTEAL

In July 2025, threat actor AuraCorp began advertising Aura Stealer as a Malware-as-a-Service (MaaS) program with multiple subscription tiers on underground forums.

Aura Stealer, also known as AURA Stealer, AURASTEAL, is a Windows infostealer.

Background

Starting in July 2025, the threat actor AuraCorp began marketing Aura Stealer on underground forums as a Malware-as-a-Service (MaaS) offering with several subscription tiers. This information stealer goes after credentials from more than 110 browsers, 70 applications, and over 250 browser extensions, including cryptocurrency wallets and 2FA tools, and protects its C2 traffic with AES-256 encryption. Among its standout capabilities are smooth harvesting of Chromium cookies without killing the browser process, server-side App-Bound data decryption, and a built-in payload loader that uses custom morphing to evade detection.


Source: Malpedia (Fraunhofer FKIE).