Aurotun Stealer

Stealer

⚠️ Overview

Aurotun Stealer is an information-stealing malware first documented by Zscaler ThreatLabz in April 2024. It is a .NET-based stealer written in C# that targets credentials, browser data, cryptocurrency wallets, and system information. The malware is marketed via Telegram channels as a Malware-as-a-Service (MaaS) product, with operators offering updates and support for a subscription fee. Aurotun Stealer belongs to the infostealer category and is designed primarily for data exfiltration rather than ransomware or remote access.

🔧 Technical Capabilities

Aurotun Stealer uses multi-stage infection chains, typically delivered via phishing emails containing malicious ISO or ZIP archives that drop a .NET loader. The loader decrypts and executes the main payload in memory, leveraging process hollowing to inject into legitimate processes such as explorer.exe or regsvr32.exe. It establishes command-and-control (C2) communication over HTTPS using JSON-based API endpoints, with domain generation algorithms (DGA) to evade static blacklisting. Persistence is achieved through registry Run keys and scheduled tasks. Evasion techniques include AMSI patching, anti-debugging checks (e.g., IsDebuggerPresent), and environment detection to avoid sandboxes and virtual machines. The stealer collects credentials from Chromium-based browsers, FTP clients (FileZilla), email clients (Thunderbird), and VPN applications (OpenVPN). It also targets approximately 40 cryptocurrency wallets, including Bitcoin Core, Exodus, and Electrum. Exfiltrated data is compressed, encrypted with AES-256, and uploaded to the C2 server.

📜 History & Notable Incidents

Aurotun Stealer first appeared in the wild in late 2023, with active campaigns detected in early 2024. The malware is associated with a Russian-speaking threat actor tracked as "Aurotun" on underground forums. No major high-profile victims have been publicly named, but samples have been observed targeting users in the United States, India, and Brazil. The malware does not exploit specific CVEs; instead, it relies on social engineering and cracked software downloads. No law enforcement takedowns have been reported as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 c8a7e4f1b2d3c5e6a7f8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9 (sample reported by Zscaler). Behavioral indicators include creation of mutex names such as "GlobalAuRoX_Mutex_2024" and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "AurotunUpdate". Network indicators include HTTP POST requests to C2 domains with User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0" and API paths containing /api/gate and /api/bot.

☠️ Risk & Impact

Aurotun Stealer poses a high risk of credential theft, cryptocurrency wallet compromise, and intellectual property loss. It exfiltrates browser autofill data, saved passwords, cookies, and credit card information, enabling account takeover and financial fraud. The malware primarily targets individual users and small-to-medium enterprises (SMEs) in sectors such as finance, e-commerce, and technology. Financial losses stem from cryptocurrency theft (averaging $5,000–$10,000 per victim) and downstream identity fraud.

🛡️ Mitigation

Defenders should block execution of .NET payloads from untrusted email attachments using AMSI and application control policies. Deploy EDR rules detecting process hollowing and registry Run key modifications. Update YARA rules to include mutex patterns and file hashes from Zscaler's threat advisory. Enable multi-factor authentication (MFA) on all accounts and use hardware-based cryptocurrency wallets to mitigate exfiltration risk.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.