AuraStealer Infostealer Emerges with 48 C2 Domains Targeting Users

AuraStealer Infostealer Emerges with 48 C2 Domains Targeting Users

First seen 3 Mar 2026, 06:10 UTC GbhackersCybersecuritynewsCyberpress 49.4

Article Content

Browse articles
ThreatCluster

AuraStealer, a new infostealer malware, has been active since mid-2025, developed by a group of Russian-speaking individuals. It was first introduced on underground forums in July 2025 and is currently utilizing 48 command and control (C2) domains in ongoing campaigns to target users.

Timeline

2025-01-01
Lumma stealer infrastructure disruption occurred
2025-07-01
AuraStealer first appeared on underground hacker forums
2026-03-03
AuraStealer reported in cybersecurity news articles