BHIS ActiveSOC investigated an Aur0ra ransomware intrusion that began with vishing after aggressive email bombing, then escalated into custom C2 activity and noisy lateral movement. The attackers used Xray-core disguised as ChromeUpdate.exe and ConnectivityHost.exe, while the locker encrypted files in place and dropped the !!!README!!!DO_NOT_DELETE.txt ransom note. #Aur0ra #Xray-core #ChromeUpdate.exe #ConnectivityHost.exe #README_DO_NOT_DELETE.txt
Keypoints
- Aur0ra gained initial access through vishing after email bombing.
- The group used Xray-core as a disguised command-and-control tunnel.
- Malicious binaries were hidden as ChromeUpdate.exe and ConnectivityHost.exe.
- Lateral movement was noisy and included SMB, LDAP, WinRM, RDP, and RPC.
- The locker encrypted files in place and dropped !!!README!!!DO_NOT_DELETE.txt.
Read More: https://activesoc.blackhillsinfosec.com/blog/introducing-the-aur0ra-ransomware-group/