Ransomware Victim: Aerospace & Advanced Composites GmbH (aurora)

Fecha
22 Jun 2026
Actor
aurora
Tipo
Ransomware
Pais
United States
Sector
Manufacturing
Confianza
high
65
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

1IOCs
0TTPs
auroraActor
United StatesPais
Executive Summary
Victima de ransomware reportada en el dashboard de aurora.

Key Points

  • Ransomware Dashboard
  • Fuente original

Aerospace & Advanced Composites GmbH

Victima de ransomware reportada en el dashboard de aurora.

CampoValor
Grupoaurora
PaisDE
SectorManufacturing
Fecha2026-06-22T14:50:58.039216+00:00

Detalles

*** (AAC) β€” an Austrian space-materials R&D company headquartered in Wiener Neustadt, with deep ties to the European Space Agency. Obtained two complete NAS snapshots spanning 30+ years of operations: aacdata (31 December 2022) β€” 123 GB: the complete Testhouse, R&D, and engineering share, including the ESA thermal vacuum test archive, polymer composites formulations, and 22 Outlook PST email backups. aacdata1 (14 January 2025) β€” 86 GB: the administrative share, including managing director's full PC backup (browser credentials, passport scans), 15 years of financial statements, shareholder agreements, and the IT credentials master spreadsheet. BMD_DATA β€” 34 MB: the complete BMD business software accounting database with employee payroll, SEPA payments, and VAT declarations. done/ β€” Bitlocker recovery keys for 12 endpoints and WMI system dumps. The exposed material includes: 4 passport scans, 1 social security number, 25 employees' complete HR files, 50–100+ job applicant CVs β€” the full identity-theft toolkit for the workforce plus third-party data subjects. The IT credentials master spreadsheet (AAC CODES.xlsx) containing every system password, plus browser-stored logins for ESA SSO, the company's IT provider, and industrial suppliers. 12 Bitlocker recovery keys enabling full-disk decryption of 6 company laptops. 123 GB of ESA thermal vacuum test data β€” 30+ years of space-grade materials testing that represents the company's core competitive advantage and cannot be recreated. 137 executed NDAs with partners including Airbus, RUAG, Safran, Thales, ESA, BMW, Tesla, Google, Samsung SDI, CERN, DLR, and 126 others. 15 years of annual financial statements, bank records, insurance policies, and shareholder agreements β€” the company's entire financial anatomy laid bare.

Referencias

Diamond Model

Adversary
aurora
Ver perfil →
Victim
Ransomware Victim: Aerospace & Advanced Composites GmbH (aurora)
United States
Capability
Ransomware
Filtracion: 123 GB
Infrastructure
Sin infraestructura confirmada

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
File CODES.xlsx Artefacto observado VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor aurora en el blog → Ver aurora en IntelTracker → URL IntelTracker: u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion → Fuente OSINT: u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion → Buscar aurora en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes