# AURA stealer

**URL:** <https://community.emergingthreats.net/t/aura-stealer/3108>\
**Category:** Rule Signatures\
**Created:** [November 13, 2025, 12:03pm UTC](https://community.emergingthreats.net/t/aura-stealer/3108 "2025-11-13T12:03:24Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![g0njxa](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/g0njxa/32/364_2.png) [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Post date:** [November 13, 2025, 12:03pm UTC](https://community.emergingthreats.net/t/aura-stealer/3108/1 "2025-11-13T12:03:24Z")

</div>

I am very sceptical about everything that is detected as Lumma Stealer since September 2025, when the administration of Lumma decided to vanish. Since that moment, everything related to Lumma should be thougth twice or even 3 times before associating to them.

An example is AURA stealer, with a C2 communication very similar to Lumma, which is causing sever mislabeling. Example of AURA stealer from today:  
[Analysis U1t-KMSpico.rar (MD5: 2FC8158F220185E6F5B980E899F2CD55) Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/14a16b11-a42b-4857-a752-4a32d984a98b)

This stealer is gaining reputation increasingly over these months also provoked by disruptions of other malware families. Please take a look

Is it possible to add detection to AURA stealer labeling correctly and separately from Lumma?

---

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [November 17, 2025, 6:54pm UTC](https://community.emergingthreats.net/t/aura-stealer/3108/2 "2025-11-17T18:54:40Z")

</div>

Thanks @g0njxa ! @ishaughnessy was taking a look at this today - the downloaded RAR from any.run is itself encrypted - he’ll be in touch.

---

<div class="post-metadata">

**Author:** ![g0njxa](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/g0njxa/32/364_2.png) [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Post date:** [November 17, 2025, 7:21pm UTC](https://community.emergingthreats.net/t/aura-stealer/3108/3 "2025-11-17T19:21:36Z")

</div>

@ishaughnessy @rgonzalez oh yeah im very sorry i didn’t post the password

RAR password is windows

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [November 21, 2025, 6:38pm UTC](https://community.emergingthreats.net/t/aura-stealer/3108/4 "2025-11-21T18:38:39Z")

</div>

hey @g0njxa - Thanks for bringing this to our attention! This week I’ve been talking to some of the researchers who handle our Lumma automation and config extraction to get some insight into how these are handled.

After reviewing a few samples we found the config extracted will sometimes contain at least one domain which is definitely Lumma which results in the classification, but this may be residual from the actor not cleaning up the config completely before new campaigns. This said, we only reviewed a limited number of samples so it’s not a complete view.

We will keep an eye out and update our automation process to handle Aura going forward based on telemetry we see. I was curious and found that the trend of Lumma (DNS) sigs being released drops off significantly between July and October which correlates with what you’ve seen.

 ![JSON-preview](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/2X/d/d1ff0314484acb5bb373379142011f2156fdb094.png)

Here are a few signatures I got in yesterday with traffic from your sample + a few pivots

```auto
ET MALWARE Aura Stealer CnC Exfil (POST) - 2065858
ET MALWARE Aura Stealer CnC Response (false) - 2065862
ET MALWARE Aura Stealer CnC Response (true) - 2065861
ET MALWARE Aura Stealer Conf Checkin (POST) - 2065859
ET MALWARE Aura Stealer Victim Checkin (GET) - 2065860
ET MALWARE Observed Aura Stealer Domain (magicupdate .cfd in TLS SNI) - 2065865
ET MALWARE Observed Aura Stealer Domain (mscloud .cfd in TLS SNI) - 2065856
ET MALWARE Observed Aura Stealer Domain (searchagent .cfd in TLS SNI) - 2065857
ET MALWARE Observed DNS Query to Aura Stealer Domain (magicupdate .cfd) - 2065864
ET MALWARE Observed DNS Query to Aura Stealer Domain (mscloud .cfd) - 2065854
ET MALWARE Observed DNS Query to Aura Stealer Domain (searchagent .cfd) - 2065855

```

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [November 21, 2025, 8:19pm UTC](https://community.emergingthreats.net/t/aura-stealer/3108/5 "2025-11-21T20:19:00Z")

</div>

I just stumbled across this, very cool you got an interview 🔥🔥🔥

[https://g0njxa.medium.com/approaching-stealers-devs-a-brief-interview-with-aura-9b513369e117](https://g0njxa.medium.com/approaching-stealers-devs-a-brief-interview-with-aura-9b513369e117)

---

<div class="post-metadata">

**Author:** ![g0njxa](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/g0njxa/32/364_2.png) [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Post date:** [November 22, 2025, 2:22am UTC](https://community.emergingthreats.net/t/aura-stealer/3108/6 "2025-11-22T02:22:03Z")

</div>

This is wonderful, thanks to you for all the amazing work!

---

<div class="post-metadata">

**Author:** ![chekin88](https://avatars.discourse-cdn.com/v4/letter/c/958977/32.png) [@chekin88](https://community.emergingthreats.net/u/chekin88)\
**Post date:** [November 25, 2025, 11:07am UTC](https://community.emergingthreats.net/t/aura-stealer/3108/7 "2025-11-25T11:07:30Z")

</div>

Hi, guys

We’ve found some anyrun tasks that produce alert on sid 2065860

> **[Analysis importantdou.exe (MD5: 5BD96CA01C820467057D58E03FF01BA8) Malicious...](https://app.any.run/tasks/a6fb8b70-1bb4-44d8-98ae-64ca1fc1a368)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/2X/7/70ee6a12152f37805bcaa1c75ac2ee33733fc294.png)

HTTP request to RMM tool server, you can see alerts:

```auto
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)

ET INFO Observed DNS Query to RMM Domain (gotoresolve .com)

```

Alert for ET MALWARE Aura Stealer Victim Checkin (GET) sid: 2065860 we found in our tool during retroscan public PCAPs

Best regards,  
Evgeny Bechkalo, AVLab Positive Technologies

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [November 25, 2025, 4:26pm UTC](https://community.emergingthreats.net/t/aura-stealer/3108/8 "2025-11-25T16:26:00Z")

</div>

Thanks for notifying us, `2065860` shouldn’t be alerting on logmein traffic so I’ll get this updated today.

The other two signatures are working as designed. They’re set as INFO and shouldn’t affect the verdict of whether or not something is malicious.

Thanks!  
Isaac
