Aurora has posted 14 victims in the past 30 days, a pace concentrated heavily on manufacturing targets (7 of the recent sample) with Germany as the dominant geography, followed by the US and Netherlands; recent claims include German metalworking and laser-equipment firms alongside a US installation contractor and an Austrian retailer. The group is tracked under a name also tied to a Go-based malware family that has circulated among multiple criminal operators since 2022, sold in underground markets as an infostealer and botnet alongside its ransomware use, though attribution and tooling overlap across users of the name should be treated as claimed rather than confirmed. No MITRE ATT&CK technique set is catalogued for this cluster, so specific intrusion or encryption tradecraft cannot be characterized beyond the naming and malware lineage noted above. Victim naming shows duplicate entries per target (listed once as unknown sector/country and again with sector and country populated), consistent with staggered enrichment of claims rather than distinct incidents. Activity so far in 2026 shows no single-