A new and sophisticated threat in the infostealer landscape is emerging AuraStealer. This infostealer, which debuted in mid-2025, has been gaining traction quickly and now targets a large, ever-evolving command-and-control (C2) infrastructure.
The AuraStealer malware primarily targets the theft on sensitive user information. It has been seen leveraging 48 active C2 domains, marking a significant shift in its attack tactics and capabilities.
AuraStealer first appeared on hacker forums in July 2025, introduced by a group of Russian-speaking threat actors. Since then, it has been observed in several campaigns in the wild, primarily targeting sensitive information across a range of systems.
A key aspect of AuraStealer’s strategy is its rapidly expanding C2 infrastructure. The malware previously relied heavily on SHOP Top-Level Domains (TLDs) but has since pivoted to using CFD TLDs, reflecting the group’s adaptability and attempts to avoid detection by traditional security systems.
The malware operates by connecting to a set of C2 domains that serve as control points for exfiltrating stolen credentials and other sensitive data.
These domains are now scattered across various TLDs, with 48 different C2 domains identified. This shift in domain tactics can be seen as a way to evade traditional domain blocklists and network defenses, as the attackers continue to evolve their infrastructure to avoid detection.
What makes this campaign particularly noteworthy is how the attackers are using the shifting domains to evade detection and track victim data.
With a combination of domain-switching techniques, AuraStealer has proven to be a significant threat. This evolution in tactics highlights the growing sophistication of threat actors in the infostealer space.
Technical Analysis and Indicators Of Compromise
Intrinsec’s Cyber Threat Intelligence (CTI) team conducted a thorough technical analysis of AuraStealer’s infrastructure, panel, and payload.
Their findings include over 340 indicators of compromise (IOCs) tied directly to the campaign. These IOCs offer valuable insights for defenders working to block malicious traffic and detect ongoing intrusions proactively.
Intrinsec’s research also focused on the malware’s behavior and the C2 communication between compromised systems and their operators.
The panel interface and payload analysis revealed that the attackers use a highly dynamic system, enabling them to shift domains frequently and deploy specialized tactics to avoid detection.
In addition to the shifting C2 infrastructure, the team found that AuraStealer uses a highly targeted approach to credential harvesting, enabling attackers to extract and exfiltrate sensitive data with minimal detection.
This includes credentials for a wide range of systems, from user login information to potentially even more critical business data.
Proactive Measures
The rise of AuraStealer reflects a broader trend in the infostealer ecosystem. While Rhadamantys and Vidar still dominate, the introduction of more agile and sophisticated malware, such as AuraStealer, is causing significant disruption.
For organizations, this shift requires a proactive cybersecurity approach, with detection and response capabilities that continuously adapt to counter increasingly sophisticated threats.
Intrinsec’s CTI services are essential for organizations looking to stay ahead of these evolving threats. By continuously monitoring IOCs, threat actors’ tactics, and infrastructure changes, companies can stay one step ahead.
| TLD | Sample Domains (Partial List) | Status |
|---|---|---|
| .shop | aurastealer[.]shop, panel-aura[.]shop | Active |
| .cfd | stealer-cfd[.]cfd, aura-panel[.]cfd | Rotating |
| Others | (Full 48 available in Intrinsec report) | Monitored |
Security teams must prioritize monitoring evolving C2 infrastructure, integrate actionable intelligence into their security tools, and anticipate emerging threats to prevent compromises before they occur.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.