VORANT. Threat Intelligence Sign in Get the full feed

Aurora ransomware leaks Evosys Laser data

medium threat manufacturing

Ransomware group Aurora claims a breach of German laser-welding manufacturer Evosys Laser, leaking HR, financial, and industrial control data.

Ransomware.live has indexed a listing attributed to a group tracked as Aurora claiming compromise of Evosys Laser GmbH, an Erlangen-based manufacturer of industrial laser welding systems with roughly 130 employees and subsidiaries in the US and China. The claimed dataset represents the company's full corporate repository: complete HR files for all employees (contracts, salaries, IBANs, tax and social insurance IDs, pension and medical records, including health data for two minors), a full internal infrastructure map derived from mRemoteNG configuration exports (seven named servers, domain admin credentials, internal IP ranges), and a Citrix administrator account reportedly secured with the password "Password1".

Beyond IT infrastructure exposure, the leak allegedly includes 326 GB of customer project data covering laser welding process parameters, CAD files, robot control software, and proprietary AQW process know-how — intellectual property of clear interest to Tier 1 automotive supply chain competitors. Financial statements spanning 2015–2028, executive compensation, attorney-client privileged communications, and whistleblower reports filed under Germany's HinSchG are also claimed, alongside industrial control assets: robot SRS source code, PLC programs, and nginx private keys for laser system web interfaces plus VPN configurations enabling remote access into customer sites.

This is a single-victim data-extortion posting rather than evidence of an active, ongoing intrusion or exploited vulnerability; no technical indicators, malware samples, or CVEs were disclosed in the source material. The exposure of hardcoded weak credentials, domain admin secrets, and VPN configurations tied to third-party customer environments creates meaningful downstream risk for Evosys's automotive OEM customers if the data is authentic and released.

Mentioned in this report

Threat actors aurora
Malware Aurora

Source reporting: https://www.ransomware.live/id/RXZvc3lzIExhc2VyIEdtYkhAYXVyb3Jh

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free