Aurora

  • First known sample

    2009
  • Discovery

    2010
  • Current status

    Inactive since 2011
  • Type

    Cyberespionage toolkit
  • Targeted platforms

    Windows
  • TOP targeted countries

    Afghanistan , Albania , Algeria , Austria , Azerbaijan , Belarus , Belgium , Bosnia and Herzegovina , Brazil , Bulgaria , CIS , Cambodia , China , Colombia , Cuba , Cyprus , Denmark , Eastern Europe , Egypt , Russia , USA
  • The way of propagation

    Access to network connections , Bootable CD-ROM , Direct hard disk infection , Exploits , File infection , LAN spreading , Mobile infections through already infected PCs , Peer-to-peer sharing networks , Physical access to computers , Physical media, CD-ROMs , Self-replication , Social engineering , Trojanized software installers , USB cables , USB drives , Watering hole attacks , Unknown
  • Purpose/Functions

    Cyberespionage , DDoS , Data theft , Data wiping , Remote control
  • Special features
    A 0-day vulnerability, known as CVE-2010-0249 in Internet Explorer, was used.
  • Targets

    Academia/Research , Activists , Aerospace , Business individuals , Chemical industry , Financial institutions , Information technology , Software companies
  • Artefacts/Attribution
    Elderwood team, linked with China and other groups of Chinese origin, like Comments Crew
  • Description

    An attack launched in early 2010 that affected a number of large companies, including Google and Adobe. The attackers exploited an unpatched vulnerability in Internet Explorer to download malware that would allow them to collect users’ confidential information, as well as code for a number of corporate projects.

    Additional information