SecuritylabJuly 19, 2026🇷🇺Translated from Russian

Aurorium Anti-Detect Browser Uses AI Fingerprinting Linked to Real Hardware and User Profiles to Evade Modern Anti-Fraud Systems

Aurorium is a new anti-detect browser that attempts to solve a long-standing problem in the market: fingerprints generated by formal rules that have no connection to the actual hardware or the social legend of the persona being emulated.

Core Technical Approach

Unlike most competing products that apply noise on top of Canvas and WebGL renders, Aurorium modifies rendering algorithms for fonts and anti-aliasing at the engine level. Public checks with CreepJS and BrowserLeaks showed no obvious inconsistencies. The browser also routes UDP traffic for WebRTC through the configured proxy and resolves DNS queries on the proxy side, preventing real IP leaks while keeping WebRTC enabled so that the session does not trigger obvious automation flags.

AI-Powered Fingerprint Generation

The standout feature is the Aurorium Fingerprint button. Instead of drawing parameters from a fixed rule set, the system examines the real device running the client and selects plausible but non-identical hardware (same GPU class, similar CPU family, comparable RAM). It then cross-references the chosen hardware with the target persona’s age, income level, occupation, and geographic location. This produces fingerprints that are statistically consistent with both the physical machine and the supposed user, reducing the “wealthy banker on a ten-year-old Windows 7 laptop” mismatch that modern LLM-based anti-fraud systems readily detect.

Additional Spoofing and Automation Features

Users can manually lock CPU cores, RAM size, and GPU model. Additional noise is applied to WebGPU, Client Rects, and Audio Context. The browser can emulate connected webcams and microphones, an important detail because platforms such as TikTok and KYC services flag sessions without any media devices as likely server-based. Command-line flags can be passed directly to Chromium, and options exist to disable heavy media, block Google services, and close local ports that financial platforms sometimes scan.

Team and Workflow Tools

The client integrates proxy management with smart string parsing, a built-in CRM with deadlines and subtasks, and a full-featured messenger supporting file transfer, voice messages, and read receipts across personal, team, and global channels. A mobile application allows task and chat management from iOS or Android. A synchronizer feature mirrors actions across multiple profiles for repetitive tasks such as form filling or bonus collection.

Security Audit

In February 2026 the company commissioned an external audit by Cure53, the Berlin firm previously engaged by NordVPN, Surfshark, and the Tor Project. Seven researchers spent 28 person-days examining the backend, Electron desktop client, mobile app, and website. The audit found 35 issues, including four critical vulnerabilities related to user anonymity and data integrity. All critical findings were remediated and re-verified by the auditors.

Conclusion

By combining kernel-level spoofing, hardware-aware AI fingerprinting, realistic social-context matching, and a transparent security audit, Aurorium positions itself as a technically substantive entrant in the anti-detect browser market rather than another interface variation on the same underlying engine.

Related articles

HabrFraud & Social Engineering

Behavioral Anti-Fraud: How Systems Analyze User Actions Beyond Device and Browser Fingerprints

Anti-fraud systems are shifting from static device and browser fingerprinting toward continuous behavioral analysis powered by machine learning. The article explains why matching User-Agent strings with Canvas or font rendering is no longer sufficient, as bot developers can easily synchronize these static signals. Modern defenses now record dozens of micro-events during a session, including keystroke timing, mouse trajectories, scroll speed, and focus changes, to build a dynamic Trust Score. These models are trained on large clusters of real-user behavior and flag sessions whose patterns fall outside legitimate clusters even when fingerprints appear realistic. The text details dwell time, flight time, error-correction patterns, natural hand tremor, and acceleration curves governed by Fitts’s law as key biometric markers. It also covers browser-level signals such as Event.isTrusted, CDP artifacts, and navigator.webdriver flags that reveal automation frameworks. The discussion extends to mobile sensors and concludes that perfectly error-free, mathematically smooth input is itself a strong indicator of synthetic activity.

BoletimSecFraud & Social Engineering

Free Online Panel Examines Rising Omnichannel Scams and Multichannel Fraud Tactics

The Brazilian human risk management firm Eskive is hosting its third free online panel on August 18 at 11 a.m. to address the growing threat of omnichannel cyber fraud. Experts will discuss how attackers combine multiple channels such as email, SMS, and other vectors to create more convincing social-engineering narratives that bypass traditional single-channel defenses. The event will feature CEO Priscila Meyer as moderator along with cyber threat intelligence specialist Thiago Bordini and Santa Catarina Civil Police investigator Elias Edenis. Participants will gain practical insights from real client simulations, live Q&A sessions, and interactive quizzes designed to improve organizational preparedness. The panel aims to highlight why users accustomed to recognizing basic phishing or smishing attempts remain vulnerable when fraudsters deploy coordinated, multi-channel campaigns.

BoletimSecFraud & Social Engineering

OpenAI Disables Coordinated ChatGPT Network Used for Financial Scams and Identity Forgery

OpenAI has deactivated a coordinated network of ChatGPT accounts that supported financial fraud, romance scams, and identity forgery operations. Criminals leveraged the AI to generate fake personas, translate conversations, and craft targeted messages aimed at victims across multiple schemes. The investigation originated from reports of suspicious activity observed on WhatsApp. Scammers used the tool to produce forged documents including stock confirmations, legal notices, passports, and fake financial interfaces to increase credibility. Operations typically began on social media or messaging apps, building emotional trust or urgency before requesting deposits, activation fees, or nonexistent fines. Indicators of possible human trafficking and forced labor were also uncovered through job advertisements and internal discussions about worker control in Poipet. OpenAI has blocked the accounts and shared operational indicators with law enforcement and technology companies.

AntiMalwareFraud & Social Engineering

Positive Technologies Uncovers Disinformation Factory Linking 45 Domains and 74 Telegram Channels

Researchers at Positive Technologies have exposed an integrated disinformation operation that combined fake government emails with a network of pseudo-news websites and synchronized social media channels. The campaign began with emails sent from lookalike domains such as minpromtorg.digital and gosuslugi.digital, requesting employee lists and salary data to prepare targeted phishing attacks. Parallel to the email activity, operators maintained at least 45 domains including rulenta.live and crime24.live that mixed genuine stories with fabricated content and cited nonexistent sources. These sites were amplified through dozens of Telegram channels and accounts on VKontakte, Odnoklassniki, YouTube, Instagram, and TikTok, creating a self-reinforcing loop where fabricated claims were quoted back as credible reporting. Investigators noted a possible infrastructure overlap with the cybercriminal group Rare Werewolf, although direct attribution remains unconfirmed. The operation demonstrates a complete information pipeline from initial reconnaissance via email to wide distribution of disinformation across multiple platforms.