Price: 295-585$
Buy in Telegram: @aura_corp (
https://t.me/aura_corp)
AURA Stealer is a carefully calibrated solution where every detail exists not for beauty, but for results.
It collects data from over 110 browsers, 70 applications, including wallets and 2FA, and over 250 browser extensions. That's not all: you can add any application or extension to the collection configuration at any time with just a couple of clicks.
We collect cookies from open Chromium browsers without killing the process (we don't delete cookies). Our own shellcode for decrypting App-Bound. All decryption is server-side - the build performs a minimum of suspicious actions.
There is a loader. The build weighs ~500-700 Kb and is reinforced with a morpher developed from scratch. This and much more awaits you with AURA!
About us:
Our team consists of experienced specialists with 5 to 11 years of experience.
Our developers study new technologies every day and take our code to the next level. They have been creating cutting-edge solutions for many years, and their attention to detail and pursuit of excellence allow us to always stay one step ahead.
Our system administrators ensure the stable operation and protection of our services, identifying and neutralizing problems before they arise. They have extensive experience in maintaining complex systems and are ready for any challenge.
Testers maintain the high quality and reliability of our product by testing it at all stages of development.
Support will not leave you alone with a problem and will be happy to help you resolve any issues. We value your time and effort, so we strive to provide fast and high-quality assistance.
The AURA team is a combination of talent, experience, tremendous energy, and interesting ideas.
All participants are united by one goal: to create and develop the best product of its kind, about which people will say, “This is exactly what I was looking for!”
Web:
[SPOILER="Screenshots of the panel and functionality"]
[SPOILER="Main panel"]
Main:
Here you can see statistics about your work, an informative graph (logins, wallets, cookies, passwords, cc, and applications), a world map showing the scale of your work, and a list of the top countries!
https://i.imgur.com/Nk5ih7o.png
[/SPOILER]
[SPOILER="Logs"]
Logs:
On this page, you can see:
- Convenient and flexible log filtering
- Selection of the type of filtering by one (or more)
- Mass unloading and deletion by filter
https://i.imgur.com/Yt7LMkl.png
[/SPOILER]
[SPOILER="Unloading"]
Unloading:
The page where logs are sent for bulk upload
https://i.imgur.com/GW8uIAJ.png
[/SPOILER]
[SPOILER="Credits and gaskets"]
Credits and gaskets:
Searching for credentials (links, logins, passwords) and downloading them.
Proxies:
Adding and removing personal ReverseProxy for build testing
https://i.imgur.com/wVeQWzq.png
[/SPOILER]
[SPOILER="Config"]
Config:
A well-configured standard grabber configuration is provided. In addition, you can create and customize your own configurations for any task.
Configurations can be changed “on the fly” during the spill, and the build will pick up all changes on the fly. You can add the following collection options to the configuration:
- File grabber (Standard)
- File grabber (Process name)
- Browser (Chromium)
- Browser (Gecko)
- Screenshot
- System Information
- Loader
- Recent (Recent Files)
There is an additional tab for configuring Chrome extension collection.
The standard configuration already includes ~250 extensions. You can expand this list with just a couple of clicks
https://i.imgur.com/1fUYiB3.png
https://i.imgur.com/utceVPO.png
[/SPOILER]
[SPOILER="Build"]
Build:
Convenient build configuration:
- Ability to select the build version
- Proxy selection
- Config selection
- Adding tags
- Setting a delay before start
- Additional options (Self-deletion, AntiVM)
https://i.imgur.com/lA9FRXJ.png
[/SPOILER]
[SPOILER="Telegram"]
Telegram:
- Page for linking Telegram bots
- Additional options: attach archive, add screenshot (if available), ignore empty ones
https://i.imgur.com/gEX6Ff5.png
[/SPOILER]
[SPOILER="Settings"]
Settings:
Subscription subsection
Subscription status and renewal
https://i.imgur.com/8Wmc7Vh.png
[/SPOILER]
[SPOILER="Profile"]
Profile:
Change password
Set the time zone to display the date and time in the desired time zone.
https://i.imgur.com/oRdna9Q.png
[/SPOILER]
[SPOILER="Reference"]
Reference:
Guide to working with the panel
https://i.imgur.com/QIr5IC4.png
[/SPOILER]
[/SPOILER]
At the entrance, you will be greeted by a panel built using the popular and beautiful Tabler web template.
You will get an intuitive and pleasant interface that has already proven itself among many users.
We believe that you will like the modern design and well-thought-out structure of the panel, which will create conditions for comfortable work.
A few facts:
- The panel is fast. Requests to the database pass through a caching layer and are processed almost instantly.
- Each user's data is securely protected by strict access policies.
- To maintain the speed of the database, it is regularly optimized and cleaned.
- We use powerful servers, which ensures the speed of our systems and high uptime.
- In our panel, you can customize the color scheme, choose a light or dark theme, font, and much more to your liking.
Build:
- The build is written in C++ (NtAPI/WinAPI + CRT/STL). The build size is ~500-700 Kb (varies in each build after morphing) and is compressed to 170-250 Kb by packers.
- Static link, runs on the entire Win7 - Win11 line. No dependencies, works on clean systems.
- Parts of the code that are critical for speed or stealth are built on NtAPI, less demanding parts are built on WinAPI.
- Imports are hidden, functions are obtained dynamically and cached in an encrypted hash table. Function addresses are not stored in plain text and are decrypted immediately before being called. The build contains only CRT imports and fake imports (which change when recompiled).
- Strings are encrypted and decrypted at runtime.
- Protection against double launch (dynamic mutex based on the DGA principle).
- Customizable Sleep before launch.
- AntiVM/Sandbox. Standard virtual/emulated environment checks. Can be enabled or disabled in the panel.
- AntiDebug. Nasty anti-debugging methods tightly integrated with our technologies. They will make even seasoned reverse engineers spit at their monitors. Anti-debugging cannot be disabled in the panel.
- ApiHammering. Background noise to simulate legitimate activity and randomize behavior at runtime. Random WinAPI calls and file system interactions (creating, writing, reading files) that are irrelevant to the task are scattered throughout the code.
- A powerful grabber with flexible collection customization. The panel allows you to set the initial collection path, search masks, recursion level, file size limit, folder in the archive, and other parameters depending on the type of collection.
- Very fast and compact Wildcard engine for searching files by masks from the config. While others offer only file extension searches, we allow you to build more complex rules with different levels of nesting (e.g., folder/folder*abc*def/.txt). It also supports relative paths with an exit from the initial directory to the level above (e.g., ../folder/*.txt), which is useful for collection by process name when the initial collection folder is unknown.
- The grabber has built-in protection against duplicate collection - the paths of scanned files are cached in a hash table. If the configuration is set up incorrectly, you will not receive a log with duplicate files.
- When the grabber is running, nothing is dropped to disk; archives are assembled in RAM. The log is transmitted to the server in parts, so even if the build catches a runtime detection, part of the data will already be on the server and you will not lose the entire log.
- All traffic between the build and C2 is encrypted with AES-256 and goes through the HTTPS protocol (its own wrapper over WinHTTP).
- In case of connection loss, the build cyclically waits for an internet connection, after which it continues from where it left off. In case of routing problems, it selects a random working one and continues sending.
- Protection against unencrypted file leakage. If the build is launched without encryption, a captcha window will appear. After entering the captcha, the build will run in normal mode. After crypt/packaging, the captcha does not appear.
- The build does not knock in CIS countries (CIS / former USSR)! Checking the layout and language of the system + checking the IP on the server.
The build is supplemented with a powerful morpher (obfuscator). At the moment, we have implemented the following functionality:
- String encryption
- Obfuscation of numerical constants
- Permutation
- Hiding references to global variables (access via encrypted pointers)
- Hiding function addresses (indirect calls to encrypted addresses)
- Hiding function arguments
- Garbage code generation
- False branches
- Indirect jumps (jmp to encrypted addresses)
- Control Flow Flattening
- Code virtualization
Why choose us?
When creating AURA Stealer, our team's goal was to eliminate the shortcomings of our competitors and multiply their strengths.
We offer unique features and capabilities that will help you reach new heights and stand out in the market.
Our team knows that there is always room for improvement, so we are constantly refining our product to keep you one step ahead.
Our dashboard is intuitive and easy to use—you don't need any special knowledge or skills to get started. You can always contact our support team for help or advice.
We offer flexible terms so you can choose the option that suits you best. Start with a minimum investment and increase your income, surround yourself with the “AURA of Success” together with us!
Pricing:
Basic ($295/month).
Your path to success starts here!
- Keyword search
- Search by country
- Search by date and time
- Ability to add 2 bulk uploads to the queue
- Ability to customize browser extension collection
- Add 2 graber configurations in addition to the standard one
- Ability to link 3 tags to a build
- Ability to create 2 builds (configuration template)
- Link one Telegram bot
Advanced ($585/month).
The golden mean for those who are used to winning!
- Advanced log filtering
- Ability to search by build
- Buttons for quick date selection by filter (24h, 7d, 30d)
- Search by tags
- Search by applications
- Search by wallets
- Search by IP address and ranges
- Additional options (hide empty, hide duplicates, hide downloaded)
- Mass upload limit increased to 4
- Ability to create up to 5 links for workers
- You can add 5 additional configurations in addition to the standard one
- Ability to attach up to 8 tags to each build
- Addition of a list of user agents in the build (used for tapping)
- Disabling the acceptance of new loots on a specific build
- Ability to create up to 5 builds (configuration templates)
- Ability to link up to 5 Telegram bots
Buy in Telegram: @aura_corp (
https://t.me/aura_corp)
User Agreement and Refund Policy
[SPOILER=“User Agreement and Refund Policy”]
User Agreement and Refund Policy
1. General Terms and Conditions
1.1 This User Agreement governs the relationship between AURA (hereinafter referred to as “We”) and the user (hereinafter referred to as “User,” “You”)
in connection with the use of the AURA Stealer product (hereinafter referred to as the “Service”).
1.2 By using the Service, you agree to the terms of this Agreement. If you do not agree to its terms, please do not use the Service.
2. Access to the Service and Payment
2.1 Access to the Service is provided on a subscription basis with monthly payments or payments for several months in advance.
2.2 Payment for the subscription is considered confirmation of your agreement with the terms of this Agreement.
3. Warranties and compliance
3.1 We strive to ensure that our service is available 24/7 and functions as described, but we do not guarantee that there will be no downtime or errors.
3.2 In the event of significant discrepancies from the stated description, the User has the right to request that the problems be resolved within a reasonable time.
3.3 If the problem cannot be resolved within 7 days, the User is entitled to a refund for the unused period of the subscription. 4. Refund Policy
4. Refund Policy
4.1 Refunds are possible in the following cases:
The Service does not fully or significantly correspond to the stated functions, and the problem cannot be resolved within 7 days.
The user canceled the subscription within 3 days from the start of the paid subscription without using the Service for commercial purposes.
4.2 Refunds are not possible in the following cases:
- The build was downloaded from the panel.
4.3 Refunds are made in proportion to the unused subscription period.
4.4 To request a refund, please contact the Service support team.
5. Limitation of liability
5.1 The Service is provided “as is.” We do not guarantee uninterrupted operation in the event of:
User actions that violate the instructions for using the Service.
Technical failures of third parties (hosting providers, Internet connections, etc.).
Force majeure circumstances (natural disasters, cyber attacks, actions of government agencies, etc.).
5.2 The maximum liability of the Service is limited to the amount paid by the User for the last billing period.
5.3 We are not responsible for indirect losses resulting from the use of the Service.
5.4 We are not responsible for the performance of modified/patched builds and the consequences of their use.
6. Changes to the Agreement
6.1 We reserve the right to change the terms of the Agreement at any time.
6.2 Continued use of the Service after the terms have been changed shall be deemed confirmation of your agreement to the new Agreement.
7. Disputes
7.1 Disputes shall be resolved through negotiation, and if no agreement can be reached, through arbitration by the forum or platform where this Agreement is located.
Return Policy.
If the problem falls within our responsibility under the user agreement, we offer the following compensation options:
1. Refund minus days of use. In this case, we will refund the money minus the cost of the days during which the product functioned correctly and was available for use.
With this refund option, the subscription on the account is reset to zero (the end of the subscription is set to the date and time of the refund).
2. Subscription extension. As an alternative to a refund, we can offer to extend your subscription for the number of days during which the product was unavailable or did not function properly.
This will allow you to use the product to its full extent at no additional cost.
To receive compensation, please contact our support team and provide detailed information about the issues you encountered.
We will review your request and offer the most appropriate solution in accordance with our policy.
[/SPOILER]