Threat actors linked to the Aurora ransomware operation have been observed using Cursor, an artificial intelligence powered coding assistant developed by SpaceX, to support attacks against multiple organizations, according to separate investigations by CloudSEK and Gambit Security. The findings are based on exposed infrastructure connected to the Russian speaking cybercrime group, allowing researchers to examine its toolkit, shell history, encryptor, and operational activity. CloudSEK reported that an exposed directory revealed months of activity targeting more than 20 organizations across nine countries between April and July 2026, with four victims later appearing on the group’s data leak site. Researchers also found that the operator used Cursor to plan attacks in Russian while deliberately excluding networks and domains associated with Commonwealth of Independent States countries. Aurora first came to public attention in May 2026 after CYFIRMA documented attacks primarily targeting Windows systems. According to Ransomware.Live, the group has since claimed 33 victims across countries including the United States, Germany, the Netherlands, Canada, and the United Kingdom.
Researchers found that Aurora continues to refine its attack techniques through a combination of social engineering, credential abuse, and lateral movement. In one incident previously documented by Black Hills Information Security, attackers gained initial access through aggressive email bombing followed by phone calls in which they presented themselves as IT help desk personnel. Victims were then persuaded to establish remote access using the open source utility Xray core. Once inside a network, the attackers moved laterally using SMB, LDAP, WinRM, RDP, and RPC before obtaining privileged administrator accounts. They then attempted to reduce detection by clearing logs, disabling Microsoft Defender, harvesting sensitive information, exfiltrating data, and deploying ransomware. CloudSEK also identified Windows and Linux versions of the Aurora encryptor written in Zig, with both versions compiled from the same source code. The Windows variant deletes volume shadow copies and disables System Restore through the Windows Registry, while the Linux and VMware ESXi version attempts to terminate virtual machines before beginning file encryption. Researchers also recovered a key that provided access to ransom negotiations and cryptocurrency wallet activity, revealing affiliate revenue shares ranging from 54 percent to 79 percent depending on the victim and ransom demand.
Gambit Security independently reported that Aurora operators relied on Cursor Agent, powered by Anthropic Claude Sonnet, to assist with hands on exploitation against 10 targets between April 8 and May 21, 2026. According to the researchers, attackers supplied the AI agent with credentials or an existing route into victim environments before assigning exploitation tasks. These included configuring VPN clients and Proxychains, scanning internal networks with Nmap and NetExec, identifying user privileges through BloodHound collection, conducting NTLM relay attacks using PetitPotam, Coerce Plus, PrinterBug, and Impacket ntlmrelayx, and carrying out certificate based attacks with Certipy. Researchers noted that many AI generated commands required repeated refinement before they achieved the intended objective, while some attempts ultimately failed. They also identified a Python script named esxi_finder.py that was used to locate VMware ESXi hypervisors and vCenter servers within compromised environments before ransomware deployment.
The research also highlights a broader trend of cybercriminal groups adopting commercial AI tools despite safeguards introduced by technology providers. Reuters reported that organizations affected by Aurora activity included Christeyns, Teckentrup, Helideck Certification Agency, Bayou Title, an Argentine pharmaceutical distributor, and an Italian manufacturer, although researchers did not officially identify victims. Separately, ReliaQuest disclosed a new AI assisted toolkit called Gryxa, describing it as the first case it had observed where artificial intelligence was used to build an entire initial access operation. Gryxa reportedly targets hundreds of hosts by abusing legitimate remote monitoring and management software, establishing persistence through multiple mechanisms, stealing credentials stored in Chromium based browsers, and collecting cryptocurrency wallet information. The toolkit also records remediation activity, uploads forensic information to attacker controlled infrastructure, and can temporarily disable endpoint protection products such as Microsoft Defender if communication with attacker infrastructure is interrupted before restoring them once connectivity resumes. Researchers said the toolkit was likely distributed through phishing emails after its developer bypassed AI safeguards by presenting the project as an authorized internal deployment.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.