Introducing the Aur0ra Ransomware Group

Introducing the Aur0ra Ransomware Group
BHIS ActiveSOC investigated an Aur0ra ransomware intrusion that began with vishing after aggressive email bombing, then escalated into custom C2 activity and noisy lateral movement. The attackers used Xray-core disguised as ChromeUpdate.exe and ConnectivityHost.exe, while the locker encrypted files in place and dropped the !!!README!!!DO_NOT_DELETE.txt ransom note. #Aur0ra #Xray-core #ChromeUpdate.exe #ConnectivityHost.exe #README_DO_NOT_DELETE.txt

Keypoints

  • Aur0ra gained initial access through vishing after email bombing.
  • The group used Xray-core as a disguised command-and-control tunnel.
  • Malicious binaries were hidden as ChromeUpdate.exe and ConnectivityHost.exe.
  • Lateral movement was noisy and included SMB, LDAP, WinRM, RDP, and RPC.
  • The locker encrypted files in place and dropped !!!README!!!DO_NOT_DELETE.txt.

Read More: https://activesoc.blackhillsinfosec.com/blog/introducing-the-aur0ra-ransomware-group/