Caught in 4K: The Aurora Files
An exposed directory exposed months of activity by a Russian-speaking Aurora ransomware affiliate who compromised more than twenty organisations across nine countries between April and July 2026 and then deployed Aurora encryptors written in Zig. CloudSEK and TRM Labs traced a ransom negotiation and multiple victim payments through shared laundering infrastructure, tying the operator directly to Aurora rather than a broker and linking four victims to Aurora’s public leak site. #Aurora #TRMLabs #CloudSEK #Zig

Keypoints

  • The exposed open directory was the operator’s Linux home directory and contained shell history, toolkits, Kerberos material, BloodHound data, and the Aurora encryptor itself.
  • The activity timeline spans April to July 2026 and shows repeated compromise of more than twenty organisations across nine countries.
  • Four recorded victims later appeared on Aurora’s public leak site with matching technical and organisational details.
  • CloudSEK recovered a key from the encryptor binary, observed ransom negotiations, and traced a payment on-chain with TRM Labs.
  • TRM Labs identified two confirmed victim payments and two additional likely victim payments that converged through shared laundering infrastructure.
  • The operator used Cursor in Russian to plan attacks, excluded CIS ranges and CIS-country domains, and behaved like a direct Aurora affiliate rather than an access broker.
  • The Aurora encryptor was unusually written in Zig and appeared in both Windows and Linux/ESXi variants compiled from a single codebase.

MITRE Techniques

  • [T1133 ] External Remote Services – Victim-facing actions were routed through rented SOCKS pivots and VPS infrastructure rather than direct access (‘Every victim-facing action routed through a rented SOCKS pivot’).
  • [T1087 ] Account Discovery – The operator used LDAP and SMB discovery to enumerate users, hosts, and access paths (‘NetExec driven LDAP and SMB discovery’).
  • [T1069 ] Permission Groups Discovery – BloodHound collections and AD enumeration were used to map privilege relationships (‘BloodHound collections sit alongside…’).
  • [T1482 ] Domain Trust Discovery – Kerberos and AD reconnaissance supported domain-level targeting and escalation (‘Kerberos tickets and credential material remain in place’).
  • [T1518 ] Software Discovery – The operator identified installed software and services, including Hyper-V and ESXi-related assets (‘check for a running Hyper-V management service’, ‘ESXi-discovery module’).
  • [T1110.003 ] Password Spraying – Password policy retrieval and repeated access testing were part of the discovery workflow (‘password policy retrieval’).
  • [T1110.004 ] Credential Stuffing – Cached credentials and validated credentials were used against services and accounts (‘SSL-VPN credentials validated’, ‘backup-system credentials validated’).
  • [T1558.004 ] Kerberoasting – Service tickets were targeted for offline cracking (‘Kerberoasting the same sequence’).
  • [T1558.004 ] AS-REP Roasting – Accounts without preauthentication were targeted for offline hash cracking (‘ASREPRoasting’).
  • [T1098 ] Account Manipulation – The custom noPac chain used machine-account rename steps to escalate privileges (‘machine-account rename → TGT → S4U2self’).
  • [T1550.003 ] Pass the Ticket – The noPac flow produced a TGT that was then used in subsequent privileged access (‘TGT → S4U2self’).
  • [T1649 ] Steal or Forge Kerberos Tickets – Kerberos tickets were captured and abused for access (‘Domain-administrator Kerberos tickets captured’).
  • [T1606.002 ] Forge Web Credentials – AD CS abuse was used to mint certificates for elevated access (‘Template misconfiguration → DA certificate’).
  • [T1649 ] Steal or Forge Kerberos Tickets – PKINIT/certificate-based authentication was used after AD CS abuse to obtain privileged authentication (‘DA certificate’).
  • [T1557.001 ] Adversary-in-the-Middle – NTLM relay was performed using coercion primitives such as PetitPotam and PrinterBug (‘PetitPotam / PrinterBug / DFSCoerce → relay’).
  • [T1210 ] Exploitation of Remote Services – EternalBlue/MS17-010 was used for direct compromise on a legacy SMB target (‘Remote code execution’).
  • [T1003.001 ] LSASS Memory – LSA dumps were collected from compromised systems (‘LSA dumps’).
  • [T1003.002 ] Security Account Manager – SAM dumps were collected from compromised systems (‘SAM and LSA dumps’).
  • [T1560.001 ] Archive Collected Data – PowerShell was used to create 7-Zip archives before exfiltration (‘PowerShell-driven 7-Zip archiving in 50GB chunks’).
  • [T1041 ] Exfiltration Over C2 Channel – Staged archives were pulled out after being prepared for transfer (‘staged and pulled’).
  • [T1486 ] Data Encrypted for Impact – The Aurora encryptor was deployed to encrypt files on Windows, Linux, and ESXi systems (‘encryptor itself’).
  • [T1489 ] Service Stop – The ESXi variant force-killed running virtual machines before encryption (‘force kills each one individually’).
  • [T1490 ] Inhibit System Recovery – The Windows variant deleted shadow copies and disabled System Restore (‘delete every volume shadow copy’).
  • [T1059.001 ] PowerShell – PowerShell was used for archiving and staging data (‘PowerShell-driven 7-Zip archiving’).
  • [T1027 ] Obfuscated Files or Information – The encryptor and tooling were staged in ways meant to reduce easy analysis, including unusual Zig static builds (‘Zig is a different choice’).

Indicators of Compromise

  • [Onion address ] Aurora Tor negotiation site – ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion
  • [SHA-256 ] Aurora Windows locker and Linux/ESXi locker – eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207, a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe
  • [Filename ] Ransom note and ESXi SSH banner note file – !!!README!!!DO_NOT_DELETE.txt, sshd-banner
  • [IPv4 ] Operator VPS and SOCKS relay infrastructure – 172.86.113.245, 104.194.134.167, and 2 more IPs
  • [IPv4:Port ] C2 egress check and SOCKS pivot endpoints – 167.88.167.37:50167, 45.61.148.166:21056


Read more: https://www.cloudsek.com/blog/aurora-ransomware-affiliate-ai-attack-planning-crypto-payments