Netskope Threat Labs

Aurorastealer

ATP Sandbox Adv. Heuristics

Aurorastealer (Aurora Stealer) is a Golang information stealer first advertised as malware as a service on Russian speaking underground forums in April 2022. It targets data from multiple browsers and cryptocurrency wallets, collects basic host information through WMIC commands, captures a desktop image, and exfiltrates everything to its command and control server in a single base64 encoded JSON file, and it can also act as a loader.

First seen
March 2023
Last seen
September 2026
Alert Name
Win32.Spyware.Aurorastealer
Win64.Spyware.Aurorastealer