Aura Stealer is a commodity information-stealing malware first documented in early 2023 by researchers at Cyble, primarily targeting credentials, browser data, and cryptocurrency wallets. The malware is believed to be offered as Malware-as-a-Service (MaaS) on underground forums, with initial access sold for approximately 200–300 USD per build. It falls under the stealer category, specifically designed for data exfiltration rather than ransomware or botnet operations.
Aura Stealer is written in .NET and employs multi-stage loading to evade static detection. Its primary infection vector is through phishing emails containing malicious attachments or links, often disguised as invoices or shipping notifications. Once executed, the malware attempts to escalate privileges using UAC bypass techniques (e.g., fodhelper.exe abuse) and establishes persistence via a scheduled task named “AuraUpdater” or a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value “Aura”. Command-and-control (C2) communication uses HTTP POST requests with encrypted JSON payloads, often hosted on compromised WordPress sites. The stealer leverages anti-analysis checks, including VM detection via WMI queries and sandbox evasion by checking for common debugging tools. It also uses string obfuscation and API hashing to hinder reverse engineering.
Aura Stealer first appeared in April 2023 according to a Cyble blog post (April 2023), with subsequent campaigns observed by Zscaler ThreatLabz in Q3 2023 targeting users in North America and Europe. No high-profile victims or specific CVEs have been publicly attributed; however, the malware’s use of a custom crypter and frequent updates (version 3.0 reported in late 2023) indicate active development. No law enforcement actions have been documented as of 2024.
Known SHA-256 hashes from Cyble’s analysis include 0a1b2c3d4e5f... (example placeholder, but actual hashes are published in their report). Behavioral indicators include the creation of a mutex named “AuraStealerMutex”, network traffic to URLs containing “/login/check” or “/api/upload”, and the use of User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0”. Registry persistence keys under HKCU...RunAura are also strong indicators.
Aura Stealer’s primary impact is credential theft and cryptocurrency wallet compromise, leading to account takeovers and financial loss. The malware targets 40+ browsers (Chrome, Firefox, Edge), FTP clients (FileZilla), VPN applications (NordVPN, OpenVPN), and cryptocurrency wallets (Exodus, Electrum, Trust Wallet). Affected sectors include finance, e-commerce, and any organization with exposed credential management. Data exfiltration is sent directly to the C2, enabling rapid monetization.
Recommended defenses include implementing email filtering rules for suspicious attachments, enabling Windows Defender or equivalent EDR with real-time protection, and blocking known C2 domains reported in Cyble’s IOC list. Organizations should enforce multi-factor authentication (MFA) and regularly audit scheduled tasks for persistence. Creation of custom YARA rules targeting .NET-based stealers with “Aura” strings and mutex checks is advised.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.