Threat Group Profile
aurora
● Active — last 30 days
Victim claims
31
First seen
Apr 2026
Last activity
17 Aug 2026
Tracked since
Apr 2026
Group overview
Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams from mid-2022, also sold as an infostealer/botnet under the same name on underground forums.
Preferred targets
Manufacturing · 10
Business Services · 5
Healthcare · 2
Financial Services · 2
Retail & E-Commerce · 2
Transportation/Logistics · 2
Most targeted countries
US · 9
DE · 7
NL · 3
CA · 3
GB · 2
PE · 1