Threat actors linked to Aurora ransomware (also known as Aur0ra) have been observed leveraging Cursor, an AI-powered coding assistant, to conduct attacks against at least 10 targets. The findings come from independent analyses by CloudSEK and Gambit Security, based on exposed infrastructure tied to the Russian-speaking cybercrime group. The use of AI coding tools in ransomware operations marks a notable evolution in attack methodology. The group appears to be utilizing Cursor to assist in developing or refining attack tooling. This incident highlights growing concerns about the abuse of legitimate AI development tools by ransomware operators.
Aurora (aka Aur0ra) ransomware operators, a Russian-speaking cybercrime group, leveraged the Cursor AI coding assistant (running Anthropic's Claude Sonnet) to plan and execute attacks against organizations between April and July 2026. The group used Cursor Agent to perform hands-on exploitation against 10 targets between April 8 and May 21, 2026, offloading tasks such as VPN/proxychains configuration, internal subnet scanning with Nmap/NetExec, domain enumeration via NetExec's BloodHound collector, NTLM relay attacks using PetitPotam/Coerce Plus/PrinterBug with Impacket ntlmrelayx, and certificate attacks with Certipy. Attack plans were written in Russian and CIS IP ranges and domains were explicitly excluded. Initial access was achieved via email bombing followed by vishing (posing as IT help desk) to establish remote access using the open-source utility Xray-core. Lateral movement occurred via SMB, LDAP, WinRM, RDP, and RPC. Attackers obtained high-privilege administrator accounts, cleared logs, disabled Microsoft Defender, harvested and exfiltrated data, then deployed the encryptor. Both Windows (sap.exe) and Linux/ESXi (encrypt.out) encryptors are static builds from a single Zig codebase. The Windows variant deletes volume shadow copies and disables System Restore via Registry. The Linux/ESXi variant kills all virtual machines before encryption. A Python script (esxi_finder.py) was used to scan for VMware ESXi hypervisors and vCenter servers. The ransomware operates as a RaaS with affiliates receiving 54-79% of ransom payments. A separate AI-built toolkit called Gryxa was also reported, used by a financially motivated threat actor targeting 324 hosts. Gryxa abuses legitimate RMM software for covert access, maintains persistence via scheduled tasks, bypasses Chromium App-Bound Encryption (ABE) to steal browser credentials, exfiltrates credentials via Telegram, records remediation efforts and reports them to the attacker, and disables/uninstalls endpoint protection agents (e.g., Microsoft Defender) within 10-13 minutes if the relay becomes unreachable.
1. Monitor and restrict use of AI coding assistants (e.g., Cursor) in sensitive environments and be aware they can be weaponized by attackers for exploitation planning. 2. Implement multi-factor authentication (MFA) across all remote access methods including RDP, WinRM, VPN, and SMB. 3. Monitor for and block lateral movement protocols (SMB, LDAP, WinRM, RDP, RPC) from unexpected sources. 4. Harden Active Directory Certificate Services (AD CS) against known abuse techniques; audit certificate templates for misconfigurations. 5. Deploy and maintain volume shadow copy protections and monitor Registry changes related to System Restore. 6. Enable and enforce Microsoft Defender tamper protection to prevent disabling by attackers. 7. Implement email bombing detection and user awareness training to prevent vishing/social engineering attacks posing as IT help desk. 8. Monitor for use of tools such as Nmap, NetExec, BloodHound, PetitPotam, Impacket, Certipy, and Xray-core on endpoints and networks. 9. Audit and restrict RMM software usage; monitor for unauthorized RMM installations (relevant to Gryxa). 10. Protect Chromium-based browser credential stores and monitor for App-Bound Encryption bypass attempts. 11. Monitor Telegram-based data exfiltration and network traffic to attacker-controlled infrastructure. 12. Hunt for the filenames sap.exe, encrypt.out, and esxi_finder.py on endpoints. 13. Maintain and test offline backups of critical data; ensure volume shadow copies are protected. 14. Monitor VMware ESXi and vCenter for unauthorized scanning or VM shutdown commands. 15. Implement network segmentation to limit lateral movement. 16. Review and restrict high-privilege administrator account usage and monitor for privilege escalation.
Filename: sap.exe (Windows Aurora encryptor, written in Zig), Filename: encrypt.out (Linux/ESXi Aurora encryptor, written in Zig), Filename: esxi_finder.py (Python script to scan for VMware ESXi/vCenter), Tool: Xray-core (open-source utility used for remote access), Tool: Cursor AI / Cursor Agent (used for attack planning and exploitation), Tool: NetExec with BloodHound collector (domain enumeration), Tool: PetitPotam, Coerce Plus, PrinterBug (NTLM coercion), Tool: Impacket ntlmrelayx (NTLM relay attacks), Tool: Certipy (certificate attacks), Tool: Nmap (network scanning), Toolkit: Gryxa (AI-built initial access toolkit), Exfiltration channel: Telegram (used by Gryxa for credential exfiltration), Cryptocurrency wallets: cluster of four wallets used for ransom payments (specific addresses not disclosed), Affected victims: Christeyns, Teckentrup, Helideck Certification Agency, Bayou Title, Argentine pharmaceutical distributor, Italian manufacturer