Aurora ransomware gang scripts attacks with Cursor AI assistant

CloudSEK and Gambit find a Russian-speaking crew leaning on AI coding tools to plan intrusions.

CSBadmin
2 Min Read

Aurora, the Russian-speaking ransomware crew that emerged in May, leaned on the Cursor AI coding assistant to plan and execute intrusions, according to separate analyses from CloudSEK and Gambit Security.

Both firms worked from exposed infrastructure tied to the group. CloudSEK pulled months of attack data from an open directory belonging to the crew. The haul covers more than 20 organizations across nine countries from April through July, and four victims have since appeared on Aurora’s leak site. Recovered shell history shows the operator using Cursor to plan attacks in Russian while excluding CIS ranges and domains “without exception.”

Gambit observed Cursor Agent, running Anthropic’s Claude Sonnet, helping with hands-on exploitation against 10 targets between April and May. Given credentials or an existing route into a victim, the agent handled reconnaissance, subnet scanning, privilege enumeration, NTLM relay attempts, and certificate attacks, sometimes choosing next steps from its own suggestions when the attacker replied with a number.

Both Windows and Linux encryptor variants are static builds from a single Zig codebase, the firms said. The Windows version deletes volume shadow copies and disables System Restore, while the Linux and ESXi variant force-kills every virtual machine on the host before encrypting. A recovered key opened a ransom negotiation and four cryptocurrency wallets, with affiliate cuts running between 54% and 79%.

One documented entry route used aggressive email bombing followed by help desk impersonation calls to establish remote access through Xray-core, then lateral movement over SMB, LDAP, WinRM, and RDP before deploying the encryptor.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.