Aurora Malware Sold on Hacker Forums
Aurora is the name of a piece of malware being sold and distributed using hacker forums and the dark web.
The malicious actor behind Aurora uses Telegram to sell their product, much like dozens of other threat actors, due to the anonymity of the medium.
Aurora is advertised through posts and embeds that use Russian, so it's safe to assume that the malware's author is a Russian speaker as well. The advertising materials posted promise a clipper module, a stealer module, proxy functionality and bulletproof hosting.
According to the ads posted by the malware's author, Aurora also functions as a botnet that is also polymorphic.
Whether this is all true is difficult to verify, as the malware has not currently been analyzed by any research team and there is no detailed report published on it.
From the way it is advertised, it looks like a relatively feature-rich and dangerous piece of malicious software.








