VMTech
Discuss a project

Aurora ransomware group used Cursor AI in attacks on 10 targets

Aurora ransomware group used Cursor AI in attacks on 10 targets

Cursor Agent used in Aurora ransomware activity

Operators associated with the Aurora, also known as Aur0ra, ransomware group used Cursor Agent running Anthropic’s Claude Sonnet for hands-on exploitation against 10 targets between April 8 and May 21, 2026. Gambit Security said the agent was given credentials or an existing route into a victim organisation and then assigned exploitation tasks.

CloudSEK separately analysed exposed infrastructure linked to the Russian-speaking group. It found an open directory that exposed months of activity involving more than 20 organisations across nine countries from April through July 2026. Four victims were later listed on Aurora’s data-leak site.

The investigations describe commercial AI tooling being used to plan and refine conventional intrusion steps rather than replacing an attacker’s access or decision-making. CloudSEK said recovered chat history showed extensive use of Cursor to plan attack phases in Russian, including an Active Directory Certificate Services exploitation plan. The operator also instructed the assistant to exclude Commonwealth of Independent States ranges and domains.

AI-assisted tasks followed established intrusion techniques

Gambit Security observed the agent being asked to install and configure a VPN client or proxychains, connect through supplied credentials or SOCKS tunnels, and scan internal subnets with Nmap or NetExec. Other tasks included domain enumeration with NetExec’s BloodHound collector, identifying a user’s privileges, NTLM relay attempts using PetitPotam, Coerce Plus, PrinterBug and Impacket ntlmrelayx, and certificate attacks with Certipy.

Many commands did not achieve the requested result on their first attempt. Gambit Security said the operator repeatedly refined commands and scripts; some tasks ultimately succeeded, while others returned only reports of the attempts. In several cases, the agent proposed next steps and the attacker selected one by replying with its number.

The wider Aurora attack chain described by Black Hills Information Security began in one case with aggressive email bombing and follow-up calls impersonating IT help-desk staff. The attackers then established remote access with the open-source Xray-core utility. Subsequent movement involved SMB, LDAP, WinRM, RDP and RPC, followed by access to highly privileged administrator accounts, log clearing, disabling Microsoft Defender, data theft and encryption.

Shared Zig codebase targets Windows, Linux and ESXi

CloudSEK identified Windows and Linux versions of the Aurora encryptor written in Zig. The Windows sap.exe and Linux/ESXi encrypt.out binaries are static builds from a single codebase compiled for different targets. CloudSEK noted that the Windows binary retained Linux build usage examples, a remnant of the shared source tree.

The Windows version can inhibit recovery by deleting volume shadow copies and disabling System Restore through the Registry. The Linux and ESXi version attempts to forcefully kill virtual machines on a host before starting encryption. A Python script named esxi_finder.py was also used to locate VMware ESXi hypervisors and vCenter servers inside victim networks.

For businesses, the findings make identity controls and lateral-movement detection central to ransomware resilience. Restricting administrator privileges, monitoring remote management and authentication activity, protecting backups and practising containment of compromised accounts can limit the value of an initial foothold, whether attackers use AI assistance or not.

#ransomware#cybersecurity#aiagents#threatintel
Open analytics
On the site 1 views
min read 4 31.08.2026
Instagram

Aurora ransomware group used Cursor AI in attacks on 10 targets

Open the post on Instagram ↗