Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

AuraStealer

AuraStealer is an emerging malware-as-a-service (MaaS) information stealer active since mid-2025 and promoted on underground forums since July 2025. It is described as being developed and actively maintained by Russian-speaking individuals and positioned as a competitor to LummaC2 after Lumma’s disruption. AuraStealer targets Windows systems, with reporting specifically stating support from Windows 7 through Windows 11.

The malware is written in C++ and has been described as a 500–700 kB infostealer. It is marketed as capable of stealing data from more than 110 browsers, over 70 applications, and more than 250 browser extensions. Reported theft targets include browser credentials, cookies, cryptocurrency wallet data, 2FA-related data, session cookies or tokens for services such as Discord, Telegram, and Steam, VPN configuration files, password manager databases including KeePass and Bitwarden, clipboard contents, screenshots, and files selected through configurable search modules. It can also retrieve additional collection directives from C2 and execute additional payloads.

AuraStealer uses substantial anti-analysis and evasion mechanisms. Reported techniques include indirect control-flow obfuscation, string and constant obfuscation, anti-debugging, anti-tamper checks, anti-VM and anti-sandbox checks, geolocation filtering, and exception-driven API hashing. It installs a custom exception handler before WinMain, deliberately triggers access-violation exceptions to dispatch WinAPI calls, and uses PEB walking plus hash-based API resolution. It also performs an anti-tampering check with MapFileAndCheckSumW and may display a code-entry dialog when run without a protective layer to hinder sandboxing. For Chromium data theft, AuraStealer reportedly includes an Application-Bound Encryption bypass by spawning a browser in headless mode, injecting code, and invoking IElevator::Decrypt using NTDLL syscalls and Heaven’s Gate.

Its configuration is embedded in the binary and encrypted with AES-CBC. Network communications are also described as AES-CBC encrypted and Base64-encoded. Reported C2 workflow includes connectivity checks to 1.1.1.1:53 and use of /api/live, /api/conf, and /api/send endpoints. Intrinsec identified 48 AuraStealer C2 domains from more than 200 VirusTotal samples, noting use of low-cost .SHOP and .CFD domains and Cloudflare reverse proxying, with newer versions shifting toward .CFD.

AuraStealer is sold via subscription and includes a management panel for campaign operations and stolen-data handling. Reported pricing includes a Basic tier at $295/month and an Advanced tier at $585/month, with a temporary two-week Trial tier also observed. The panel supports build generation, log filtering, dashboards with geographic breakdowns, and Telegram bot integration. Reporting states the offering was initially Russian-language and later expanded to Russian and English.

Observed delivery is primarily through social-engineering-driven ClickFix or Scam-Yourself campaigns. Multiple reports describe TikTok videos masquerading as software activation or product activation tutorials that instruct victims to run elevated PowerShell commands, effectively causing users to infect their own systems. Additional observed delivery methods include cracked games or software, Visual Basic scripts, self-extracting archives, Donut shellcode loaders, malicious .NET DLLs, DLL sideloading, process injection into legitimate Windows binaries such as regasm.exe and SndVol.exe, a loader called Soulbind, a fake cleaning tool named Gcleaner, and delivery alongside GlassWorm via a malicious VS Code extension.

High-confidence infrastructure and operational details directly mentioned in the content include underground promotion under the username AuraCorp on XSS on July 8, 2025, later posts on Exploit, Darkmarket, Blackbones, Sinister, Enclave, and Darkstash, and C2 domain patterns using .SHOP and .CFD behind Cloudflare. The malware has been repeatedly associated with TikTok-based Scam-Yourself campaigns and broader cracked-software distribution.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

14 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

2 techniques
T1059.001PowerShellEvidence1

"Viewers were told to open PowerShell with administrator privileges and run a short one-line command. That command quietly downloaded and executed an AuraStealer sample"

T1204User ExecutionEvidence1

...serve ClickFix-style instructions that drop a new variant of the Atomic Stealer...

Privilege Escalation

1 technique
T1055Process InjectionEvidence1

"AuraStealer was injected into legitimate Windows processes like regasm.exe and SndVol.exe using Visual Basic scripts, self-executing archives, and Donut shellcode loaders."

Stealth

2 techniques
T1055Process InjectionEvidence1

"AuraStealer was injected into legitimate Windows processes like regasm.exe and SndVol.exe using Visual Basic scripts, self-executing archives, and Donut shellcode loaders."

T1218System Binary Proxy ExecutionEvidence1

"injected into legitimate Windows processes like regasm.exe and SndVol.exe"

Credential Access

4 techniques
T1539Steal Web Session CookieEvidence1

"session cookies from Discord, Telegram, and Steam"

T1552Unsecured CredentialsEvidence1

"VPN configuration files"

T1555Credentials from Password StoresEvidence1

"password manager databases from tools like KeePass and Bitwarden"

T1555.003Credentials from Web BrowsersEvidence1

"The range of data the malware collects is striking — browser credentials... session cookies from Discord, Telegram, and Steam"

Collection

2 techniques
T1113Screen CaptureEvidence1

"screenshots of the victim’s screen"

T1115Clipboard DataEvidence1

"clipboard contents"

Command and Control

4 techniques
T1071.001Web ProtocolsEvidence1

"well-structured command-and-control (C2) infrastructure... 48 C2 domain names... routes all traffic through Cloudflare as a reverse proxy."

T1090ProxyEvidence1

...routing all traffic through Cloudflare as a reverse proxy to conceal the real server.

T1090.002External ProxyEvidence1

"To hide the real server, the actor routes all traffic through Cloudflare as a reverse proxy."

T1105Ingress Tool TransferEvidence1

"That command quietly downloaded and executed an AuraStealer sample on the target’s machine"; "Soulbind retrieved and executed the payload from remote servers."

ACTIVITY FEED

Recent activity

9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping14

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.