Skip to content
AuraStealer Infostealer Emerges with 48 C2 Domains Targeting Users

AuraStealer Infostealer Emerges with 48 C2 Domains Targeting Users

First seen 3 Mar 2026, 06:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

AuraStealer, a new infostealer malware, has been active since mid-2025, developed by a group of Russian-speaking individuals. It was first introduced on underground forums in July 2025 and is currently utilizing 48 command and control (C2) domains in ongoing campaigns to target users.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

Timeline

2025-01-01
Lumma stealer infrastructure disruption occurred
2025-07-01
AuraStealer first appeared on underground hacker forums
2026-03-03
AuraStealer reported in cybersecurity news articles

More articles in this cluster (3)

Following this threat?

Track AuraStealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed