Infostealer
Aurora Stealer
First advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in April 2022, Aurora Stealer is a Golang-based information stealer with downloading and remote access capabili
Aurora Stealer is a Windows infostealer.
Background
Aurora Stealer, first promoted as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in April 2022, is a Golang-based information stealer that also offers downloading and remote-access functionality. It pulls data from numerous browsers, cryptocurrency wallets, and local systems while doubling as a loader. At runtime it issues a number of commands via WMIC to gather basic host details, captures a screenshot of the desktop, and ships the stolen data to its C2 server packed into a single base64-encoded JSON file.
Source: Malpedia (Fraunhofer FKIE).