Zero Day Room
Live
Threats

Aurora Ransomware Uses Cursor AI in Attacks

Aurora ransomware actors used SpaceX's Cursor Agent AI to aid attacks on 10 victims from April to May 2026, says Gambit Security.

Aurora ransomware actors used SpaceX's Cursor Agent AI to aid attacks on 10 victims from April to May 2026, says Gambit...

The Aurora ransomware group has been using SpaceX's AI-powered Cursor Agent to automate and enhance its exploitation campaigns. Gambit Security's Threat Intelligence team detailed this abuse in a study published on August 27, 2026, noting the tool was used against 10 victims over a seven-week period.

According to the researchers, the threat actors ran the Claude Sonnet model through Cursor Agent to assist with various tasks after gaining initial access. These activities included scanning victim environments for reconnaissance, installing VPN clients, and executing certificate attacks. While the AI agent did not always succeed on its first try, its use demonstrates a continuous experimentation with AI tools to speed up malicious operations.

How the AI Agent Was Utilized

Operators provided Cursor Agent with credentials or an existing access route into victim organizations. The commands given to the AI varied in specificity.

Some instructions were broad, such as asking the agent to determine what rights a compromised user account possessed. On other occasions, attackers issued detailed directives. These included enumerating domain privileges, using tools like NetExec's BloodHound collector, and scanning internal subnets with Nmap or NetExec.

For exploitation, the agent was tasked with attempting NTLM relay attacks using tools like PetitPotam, Coerce Plus, and PrinterBug. It was also instructed to run certificate attacks with Certipy. Another common task involved installing and configuring a VPN client or proxychains to establish a persistent connection back to the victim network.

The Gambit report notes that most commands failed initially, requiring multiple refinements. Some eventually succeeded, while others failed entirely, returning only a report of the attempts to the attacker.

New Linux Variant Targets ESXi

The same study observed Aurora operators deploying a new Linux ransomware variant designed for VMware ESXi environments. The attackers used a custom NetExec LDAP module called esxi_finder.py to scan for ESXi hypervisors and vCenter servers within a compromised network.

This variant specifically encrypts virtual machine files while skipping system volumes. This approach keeps the hypervisor itself bootable, allowing the victim to read the ransom demand. Gambit researchers also identified a second cluster of activity, which they attribute with medium confidence to an Aurora operator.

This cluster targeted eight organizations across Israel, Germany, Austria, Spain, the United States, and Argentina. Aurora ransomware activity has been tracked since April 2026, with the group maintaining a data leak site and targeting organizations globally. The group's adoption of AI-assisted tools marks a significant evolution in its operational tactics.

Related coverage

More from Threats