Skip to content

Infostealer

Aurora Stealer

First advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in April 2022, Aurora Stealer is a Golang-based information stealer with downloading and remote access capabili

Aurora Stealer is a Windows infostealer.

Background

Aurora Stealer, first promoted as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in April 2022, is a Golang-based information stealer that also offers downloading and remote-access functionality. It pulls data from numerous browsers, cryptocurrency wallets, and local systems while doubling as a loader. At runtime it issues a number of commands via WMIC to gather basic host details, captures a screenshot of the desktop, and ships the stolen data to its C2 server packed into a single base64-encoded JSON file.


Source: Malpedia (Fraunhofer FKIE).