An exposed directory exposed months of activity by a Russian-speaking Aurora ransomware affiliate who compromised more than twenty organisations across nine countries between April and July 2026 and then deployed Aurora encryptors written in Zig. CloudSEK and TRM Labs traced a ransom negotiation and multiple victim payments through shared laundering infrastructure, tying the operator directly to Aurora rather than a broker and linking four victims to Auroraâs public leak site. #Aurora #TRMLabs #CloudSEK #Zig
Keypoints
- The exposed open directory was the operatorâs Linux home directory and contained shell history, toolkits, Kerberos material, BloodHound data, and the Aurora encryptor itself.
- The activity timeline spans April to July 2026 and shows repeated compromise of more than twenty organisations across nine countries.
- Four recorded victims later appeared on Auroraâs public leak site with matching technical and organisational details.
- CloudSEK recovered a key from the encryptor binary, observed ransom negotiations, and traced a payment on-chain with TRM Labs.
- TRM Labs identified two confirmed victim payments and two additional likely victim payments that converged through shared laundering infrastructure.
- The operator used Cursor in Russian to plan attacks, excluded CIS ranges and CIS-country domains, and behaved like a direct Aurora affiliate rather than an access broker.
- The Aurora encryptor was unusually written in Zig and appeared in both Windows and Linux/ESXi variants compiled from a single codebase.
MITRE Techniques
- [T1133 ] External Remote Services â Victim-facing actions were routed through rented SOCKS pivots and VPS infrastructure rather than direct access (âEvery victim-facing action routed through a rented SOCKS pivotâ).
- [T1087 ] Account Discovery â The operator used LDAP and SMB discovery to enumerate users, hosts, and access paths (âNetExec driven LDAP and SMB discoveryâ).
- [T1069 ] Permission Groups Discovery â BloodHound collections and AD enumeration were used to map privilege relationships (âBloodHound collections sit alongsideâŚâ).
- [T1482 ] Domain Trust Discovery â Kerberos and AD reconnaissance supported domain-level targeting and escalation (âKerberos tickets and credential material remain in placeâ).
- [T1518 ] Software Discovery â The operator identified installed software and services, including Hyper-V and ESXi-related assets (âcheck for a running Hyper-V management serviceâ, âESXi-discovery moduleâ).
- [T1110.003 ] Password Spraying â Password policy retrieval and repeated access testing were part of the discovery workflow (âpassword policy retrievalâ).
- [T1110.004 ] Credential Stuffing â Cached credentials and validated credentials were used against services and accounts (âSSL-VPN credentials validatedâ, âbackup-system credentials validatedâ).
- [T1558.004 ] Kerberoasting â Service tickets were targeted for offline cracking (âKerberoasting the same sequenceâ).
- [T1558.004 ] AS-REP Roasting â Accounts without preauthentication were targeted for offline hash cracking (âASREPRoastingâ).
- [T1098 ] Account Manipulation â The custom noPac chain used machine-account rename steps to escalate privileges (âmachine-account rename â TGT â S4U2selfâ).
- [T1550.003 ] Pass the Ticket â The noPac flow produced a TGT that was then used in subsequent privileged access (âTGT â S4U2selfâ).
- [T1649 ] Steal or Forge Kerberos Tickets â Kerberos tickets were captured and abused for access (âDomain-administrator Kerberos tickets capturedâ).
- [T1606.002 ] Forge Web Credentials â AD CS abuse was used to mint certificates for elevated access (âTemplate misconfiguration â DA certificateâ).
- [T1649 ] Steal or Forge Kerberos Tickets â PKINIT/certificate-based authentication was used after AD CS abuse to obtain privileged authentication (âDA certificateâ).
- [T1557.001 ] Adversary-in-the-Middle â NTLM relay was performed using coercion primitives such as PetitPotam and PrinterBug (âPetitPotam / PrinterBug / DFSCoerce â relayâ).
- [T1210 ] Exploitation of Remote Services â EternalBlue/MS17-010 was used for direct compromise on a legacy SMB target (âRemote code executionâ).
- [T1003.001 ] LSASS Memory â LSA dumps were collected from compromised systems (âLSA dumpsâ).
- [T1003.002 ] Security Account Manager â SAM dumps were collected from compromised systems (âSAM and LSA dumpsâ).
- [T1560.001 ] Archive Collected Data â PowerShell was used to create 7-Zip archives before exfiltration (âPowerShell-driven 7-Zip archiving in 50GB chunksâ).
- [T1041 ] Exfiltration Over C2 Channel â Staged archives were pulled out after being prepared for transfer (âstaged and pulledâ).
- [T1486 ] Data Encrypted for Impact â The Aurora encryptor was deployed to encrypt files on Windows, Linux, and ESXi systems (âencryptor itselfâ).
- [T1489 ] Service Stop â The ESXi variant force-killed running virtual machines before encryption (âforce kills each one individuallyâ).
- [T1490 ] Inhibit System Recovery â The Windows variant deleted shadow copies and disabled System Restore (âdelete every volume shadow copyâ).
- [T1059.001 ] PowerShell â PowerShell was used for archiving and staging data (âPowerShell-driven 7-Zip archivingâ).
- [T1027 ] Obfuscated Files or Information â The encryptor and tooling were staged in ways meant to reduce easy analysis, including unusual Zig static builds (âZig is a different choiceâ).
Indicators of Compromise
- [Onion address ] Aurora Tor negotiation site â ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion
- [SHA-256 ] Aurora Windows locker and Linux/ESXi locker â eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207, a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe
- [Filename ] Ransom note and ESXi SSH banner note file â !!!README!!!DO_NOT_DELETE.txt, sshd-banner
- [IPv4 ] Operator VPS and SOCKS relay infrastructure â 172.86.113.245, 104.194.134.167, and 2 more IPs
- [IPv4:Port ] C2 egress check and SOCKS pivot endpoints â 167.88.167.37:50167, 45.61.148.166:21056
Read more: https://www.cloudsek.com/blog/aurora-ransomware-affiliate-ai-attack-planning-crypto-payments