HackMyIP
← Back to News
2026-08-31 The Hacker News

Aurora Ransomware Group Uses AI Coding Assistant to Hit 10 Targets

RansomwareAI SecurityThreat Intel

Threat actors linked to the Aurora (Aur0ra) ransomware operation have been leveraging Cursor, an AI-powered coding assistant originally developed by SpaceX, to plan and execute intrusions against at least 20 organizations across nine countries. According to independent analyses by CloudSEK and Gambit Security, exposed infrastructure tied to the Russian-speaking cybercrime group revealed months of operational activity between April and July 2026, including shell history, tooling, and the encryptor binary itself. CloudSEK researchers noted that the operator used Cursor as an agentic coding assistant to strategize attacks in Russian, while consistently excluding Commonwealth of Independent States (CIS) IP ranges and CIS-country domains from targeting. As of writing, four victims have already been posted to Aurora's data leak site, and Ransomware.Live tracks 33 victims spanning the U.S., Germany, the Netherlands, Canada, and the U.K.

The broader attack chain typically begins with aggressive email bombing followed by phone calls impersonating IT help desk staff to establish remote access via the open-source utility Xray-core. Once inside, the operators move laterally using SMB, LDAP, WinRM, RDP, and RPC, escalate to high-privilege administrator accounts, and disable defenses by clearing logs and shutting down Microsoft Defender before exfiltrating data and deploying the encryptor. CloudSEK's analysis confirmed that both Windows and Linux/ESXi variants are static builds derived from a single Zig codebase, and the operator's recovered Cursor chat history includes a full Active Directory Certificate Services (AD CS) exploitation plan written in Russian. The Windows variant inhibits recovery by deleting volume shadow copies and disabling System Restore, while the Linux and ESXi variant forcefully terminates all virtual machines on a host prior to encryption. Organizations concerned about exposed admin credentials in such breaches can run a quick password checker to audit reuse of compromised logins.

The use of agentic AI tooling inside an active ransomware campaign reflects a wider shift in offensive tradecraft. Defenders are urged to monitor outbound connections and harden against the vishing component by enforcing help desk verification policies. Network exposures remain a primary risk factor in these intrusions, so running a port scanner against perimeter assets can help identify SMB, RDP, and WinRM services inadvertently left accessible to the internet. Additional operational indicators tied to the Aurora group, including its infrastructure and negotiation portal, continue to surface, suggesting the threat actors' leaked chat logs and binaries will likely fuel further attribution and detection engineering efforts in the coming weeks.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →