INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Aurora Ransomware Operators Utilize Cursor AI in Targeted Attacks
| 2026-08-31 11:47 HIGH LOW AI-ENABLED ATTACK · AUTONOMOUS RANSOMWARE & EXTORTION
Executive Summary
AI-generated
Threat actors associated with the Aurora ransomware group have been observed using SpaceX's artificial intelligence-powered coding assistant Cursor to break into target networks, according to independent analyses by CloudSEK and Gambit Security. The attacks were carried out against 10 targets in nine countries between April and July 2026, affecting organizations in the U.S., Germany, the Netherlands, Canada, and the U.K. with a total of 33 victims identified across these regions. The attackers used aggressive email bombing followed by phone calls posing as IT help desk personnel to gain initial access, before exploiting vulnerabilities such as SMB, LDAP, WinRM, RDP, and RPC to obtain high-privilege administrator accounts. Once inside, they cleared logs and disabled Microsoft Defender to evade detection, harvested sensitive data, deployed the encryptor, and established communication with victims through a recovered key that granted access to ransom negotiations between the threat actor and an unspecified victim.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ra•••••.live
en•••••.out
sa•••••.exe
es•••••.py
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
AuroraAurora
Target & Sectors
BENELUX
BENELUX
DACH
DACH
CIS
CIS
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
May 2026
The Aurora ransomware operators used Cursor AI to plan and execute attacks against 10 targets between April 8 and May 21, 2026.
Click on any entity below to view its context and source!
infrastructure
Cursor
CloudSEK said it identified both Windows and Linux versions of Aurora written in Zig, adding the operator's recovered chat history shows heavy use of Cursor for planning various phases of the attack.
Gambit Security, which released its own insights into the activity, said it observed the Aurora operator using Cursor Agent, running Anthropic's Claude Sonnet, to help with hands-on exploitation against 10 targets between April 8 and May 21, 2026.
infrastructure
Windows
CloudSEK said it identified both Windows and Linux versions of Aurora written in Zig, adding the operator's recovered chat history shows heavy use of Cursor for planning various phases of the attack.
"Both encryptor binaries, the Windows sap.exe and the Linux/ESXi encrypt.out, are static builds from a single Zig codebase, compiled for different targets rather than written twice," the company noted.
"The Windows binary even carries the Linux build's usage examples inside it, a leftover from sharing one source tree across both platforms.
"
The Windows variant is also equipped to inhibit system recovery through the deletion of volume shadow copies and disabling System Restore directly via the Registry.
infrastructure
Linux
CloudSEK said it identified both Windows and Linux versions of Aurora written in Zig, adding the operator's recovered chat history shows heavy use of Cursor for planning various phases of the attack.
"Both encryptor binaries, the Windows sap.exe and the Linux/ESXi encrypt.out, are static builds from a single Zig codebase, compiled for different targets rather than written twice," the company noted.
"The Windows binary even carries the Linux build's usage examples inside it, a leftover from sharing one source tree across both platforms.
The Linux and ESXi variant, on the other hand, attempts to forcefully kill every single virtual machine on the host prior to starting encryption.
victims
10 Targets
Gambit Security, which released its own insights into the activity, said it observed the Aurora operator using Cursor Agent, running Anthropic's Claude Sonnet, to help with hands-on exploitation against 10 targets between April 8 and May 21, 2026.
May 21, 2026
Threat actors used a Python script called "esxi_finder.py" to scan for VMware ESXi hypervisors and vCenter servers in victim networks.
Click on any entity below to view its context and source!
infrastructure
Windows
Specifically, after the visible RMM implant is removed, a hidden malware component collects Windows logs and host artifacts and uploads them to attacker-controlled infrastructure.
infrastructure
Linux
"
In addition, attacks involving the Linux version have leveraged a Python script ("esxi_finder.py") to scan for VMware ESXi hypervisors and vCenter servers inside a victim network.
infrastructure
324 hosts
Gryxa Toolkit Emerges
It also follows the discovery of a new AI-assisted toolkit dubbed Gryxa that's used by a financially motivated threat actor to run an initial-access operation targeting 324 hosts.
July 2026
Threat actors using Cursor AI planned attacks against 10 targets, primarily targeting Windows systems.
Click on any entity below to view its context and source!
infrastructure
Cursor
"The operator used Cursor, an agentic coding assistant, to plan attacks in Russian, while excluding CIS [Commonwealth of Independent States] ranges and CIS-country domains, without exception," CloudSEK noted.
infrastructure
Windows
Details about Aurora first emerged in late May 2026, with CYFIRMA
highlighting
attacks primarily targeting Windows systems and its continued technical development through incremental updates and feature expansion.
2026/08/31
Threat actors associated with Aurora ransomware have been observed using SpaceX's artificial intelligence-powered coding assistant Cursor to break into target networks.
Click on any entity below to view its context and source!
infrastructure
Cursor
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets.
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from
CloudSEK
and
Gambit Security
.
victims
10 Targets
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets.
victims
33 victims
Live lists
33 victims
located in the U.S., Germany, the Netherlands, Canada, and the U.K.
In one case
detailed
by Black Hills Information Security earlier this month, initial access was achieved via aggressive email bombing followed by
makin…
victims
20 organizations
CloudSEK said the exposed open directory leaked "months of activity" that was active against more than 20 organizations across nine countries between April and July 2026.
Tactical Metrics
Metrics
infrastructure
Cursor
Affected Product
Click for context!
"The operator used Cursor, an agentic coding assistant, to plan attacks in Russian, while excluding CIS [Commonwealth of Independent States] ranges and CIS-country domains, without exception," CloudSEK noted.
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets.
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from
CloudSEK
and
Gambit Security
.
CloudSEK said it identified both Windows and Linux versions of Aurora written in Zig, adding the operator's recovered chat history shows heavy use of Cursor for planning various phases of the attack.
Gambit Security, which released its own insights into the activity, said it observed the Aurora operator using Cursor Agent, running Anthropic's Claude Sonnet, to help with hands-on exploitation against 10 targets between April 8 and May 21, 2026.
Metrics
victims
33
Victims
Live lists
33 victims
located in the U.S., Germany, the Netherlands, Canada, and the U.K.
In one case
detailed
by Black Hills Information Security earlier this month, initial access was achieved via aggressive email bombing followed by
makin…
Metrics
victims
10
Targets
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets.
Gambit Security, which released its own insights into the activity, said it observed the Aurora operator using Cursor Agent, running Anthropic's Claude Sonnet, to help with hands-on exploitation against 10 targets between April 8 and May 21, 2026.
Metrics
infrastructure
Windows
Affected Product
Details about Aurora first emerged in late May 2026, with CYFIRMA
highlighting
attacks primarily targeting Windows systems and its continued technical development through incremental updates and feature expansion.
CloudSEK said it identified both Windows and Linux versions of Aurora written in Zig, adding the operator's recovered chat history shows heavy use of Cursor for planning various phases of the attack.
"Both encryptor binaries, the Windows sap.exe and the Linux/ESXi encrypt.out, are static builds from a single Zig codebase, compiled for different targets rather than written twice," the company noted.
"The Windows binary even carries the Linux build's usage examples inside it, a leftover from sharing one source tree across both platforms.
"
The Windows variant is also equipped to inhibit system recovery through the deletion of volume shadow copies and disabling System Restore directly via the Registry.
Specifically, after the visible RMM implant is removed, a hidden malware component collects Windows logs and host artifacts and uploads them to attacker-controlled infrastructure.
Metrics
infrastructure
Linux
Affected Product
CloudSEK said it identified both Windows and Linux versions of Aurora written in Zig, adding the operator's recovered chat history shows heavy use of Cursor for planning various phases of the attack.
"Both encryptor binaries, the Windows sap.exe and the Linux/ESXi encrypt.out, are static builds from a single Zig codebase, compiled for different targets rather than written twice," the company noted.
"The Windows binary even carries the Linux build's usage examples inside it, a leftover from sharing one source tree across both platforms.
The Linux and ESXi variant, on the other hand, attempts to forcefully kill every single virtual machine on the host prior to starting encryption.
"
In addition, attacks involving the Linux version have leveraged a Python script ("esxi_finder.py") to scan for VMware ESXi hypervisors and vCenter servers inside a victim network.
Metrics
victims
20
Organizations
CloudSEK said the exposed open directory leaked "months of activity" that was active against more than 20 organizations across nine countries between April and July 2026.
Metrics
infrastructure
324
Hosts
Gryxa Toolkit Emerges
It also follows the discovery of a new AI-assisted toolkit dubbed Gryxa that's used by a financially motivated threat actor to run an initial-access operation targeting 324 hosts.
Intelligence Sources
The Hacker News
2026-08-31
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T12:04
Comprehensive Tactical Telemetry
Highly Correlated Entities
32x
organisation
Identified Entity
Commonwealth of Independent States
entity
6x
target region
Target Country
Russian Federation
country
4x
tactic
Cyber Operation Type
Ransomware
tactic
3x
infrastructure
Affected Product
Cursor
software
3x
timeline
Temporal Reference
May 21, 2026
date
2x
general metric
%
54
%
Contextual Telemetry
Context Block
14 METRICS
source region
Origin Country
Russian Federation
country
target region
Target Region
CIS
region
victims
Victims
33
victims
industry
Targeted Sector
Pharmaceutical
sector
malware
Malware Payload
Aurora
tool
victims
Targets
10
targets
attribution
Attributing Entity
CloudSEK
authority
general metric
April
8
april
malware
Offensive Tool
Bloodhound
tool
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
victims
Organizations
20
organizations
general metric
Kb
200
kb
infrastructure
Hosts
324
hosts
general metric
Minutes
10
minutes
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.