Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Aurora Stealer Leverages Shapeshifting Tactics And Popular Applications To Target Users

January 22, 2023

A threat actor was discovered mimicking legitimate websites to host and deliver the 9002 RAT, also known as Aurora, Hydraq, and McRat. Binary padding, system checks, and obfuscation were used in an attempt to evade antivirus software detection. The malicious software exfiltrates a range of data including system information and data from web browsers, crypto wallets, and certain user directories.