aurora
Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams from mid-2022, also sold as an infostealer/botnet under the same name on underground forums.
A Go-based ransomware group active since 2022, sold as an infostealer/botnet on underground forums.
Aurora is a ransomware group active since mid-2022, distributing multi-purpose Go-based malware utilized by multiple criminal teams and sold as an infostealer/botnet on underground forums. The group primarily targets sectors like Manufacturing, Professional Services, Retail, Technology, Healthcare, Financial Services, and Agriculture across Germany, the US, the Netherlands, the UK, Canada, Australia, and others. Their key TTPs involve deploying versatile Go-based malware for both ransomware attacks and data theft. Defenders should focus on detecting Go-based payloads, monitoring for anomalous C2 traffic, and strengthening defenses against email-borne phishing vectors.
Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams from mid-2022, also sold as an infostealer/botnet under the same name on underground forums.
Aurora targets Manufacturing, Professional Services, Retail, Technology, Healthcare, Financial Services, and Agriculture sectors.
Defenders should focus on detecting Go-based payloads, monitoring for anomalous C2 traffic, and strengthening defenses against email-borne phishing vectors.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.