INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Aurora Ransomware Operators Utilize Cursor AI in Targeted Attacks

| 2026-08-31 11:47 HIGH LOW AI-ENABLED ATTACK · AUTONOMOUS RANSOMWARE & EXTORTION
Executive Summary
AI-generated
Threat actors associated with the Aurora ransomware group have been observed using SpaceX's artificial intelligence-powered coding assistant Cursor to break into target networks, according to independent analyses by CloudSEK and Gambit Security. The attacks were carried out against 10 targets in nine countries between April and July 2026, affecting organizations in the U.S., Germany, the Netherlands, Canada, and the U.K. with a total of 33 victims identified across these regions. The attackers used aggressive email bombing followed by phone calls posing as IT help desk personnel to gain initial access, before exploiting vulnerabilities such as SMB, LDAP, WinRM, RDP, and RPC to obtain high-privilege administrator accounts. Once inside, they cleared logs and disabled Microsoft Defender to evade detection, harvested sensitive data, deployed the encryptor, and established communication with victims through a recovered key that granted access to ransom negotiations between the threat actor and an unspecified victim.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ra•••••.live
en•••••.out
sa•••••.exe
es•••••.py
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
AuroraAurora
Target & Sectors
BENELUX BENELUX DACH DACH CIS CIS NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎May 2026
The Aurora ransomware operators used Cursor AI to plan and execute attacks against 10 targets between April 8 and May 21, 2026.
infrastructure Cursor
infrastructure Windows
infrastructure Linux
victims 10 Targets
‎May 21, 2026
Threat actors used a Python script called "esxi_finder.py" to scan for VMware ESXi hypervisors and vCenter servers in victim networks.
infrastructure Windows
infrastructure Linux
infrastructure 324 hosts
‎July 2026
Threat actors using Cursor AI planned attacks against 10 targets, primarily targeting Windows systems.
infrastructure Cursor
infrastructure Windows
‎2026/08/31
Threat actors associated with Aurora ransomware have been observed using SpaceX's artificial intelligence-powered coding assistant Cursor to break into target networks.
infrastructure Cursor
victims 10 Targets
victims 33 victims
victims 20 organizations
Tactical Metrics
Metrics
infrastructure
‎Cursor
Affected Product
Metrics
victims
33
Victims
Metrics
victims
10
Targets
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
victims
20
Organizations
Metrics
infrastructure
324
Hosts
Intelligence Sources