Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-01 ยท updated: 2026-09-01 ยท tags: [incident, aurora, ransomware, cursor, ai, claude, cloudske, gambit-security, zig] ยท confidence: high ยท severity: high ยท affected_sectors: [Global] ยท au_impact: false

Aurora Ransomware Operators Use Cursor AI to Plan and Execute Attacks

Summary

Security firms CloudSEK and Gambit Security independently documented Aurora (Aur0ra) ransomware operators using the AI coding assistant Cursor to plan and carry out attacks in 2026.

Details

An exposed open directory leaked the group's toolkit, shell history and encryptor, revealing "months of activity" against more than 20 organisations across nine countries between April and July 2026. The operator used Cursor "to plan attacks in Russian" while excluding CIS ranges and domains. Gambit Security observed the operator running Cursor Agent (on Anthropic's Claude Sonnet) for hands-on exploitation against 10 targets between 8 April and 21 May โ€” tasking it with VPN/proxychains setup, Nmap and NetExec subnet scans, BloodHound domain enumeration, NTLM-relay via PetitPotam/Coerce/PrinterBug, and Certipy certificate attacks.

The Windows and Linux/ESXi encryptors are static builds from a single Zig codebase; the Linux variant kills every VM on the host before encryption. Ransomware.Live lists 33 Aurora victims, mostly in the US, Germany, the Netherlands, Canada and the UK.

Assessment

This is a documented case of a financially-motivated ransomware group using a commercial agentic coding assistant as first-class exploitation tooling โ€” a step beyond the AI-assisted phishing and payload-generation seen previously. It extends the agentic-AI security story into active offensive use, with attackers accepting the agent's suggested next steps and iterating on its failed first attempts.