Aurora Used Cursor to Turn Ransomware Into a Repeatable Playbook
An Aurora ransomware affiliate left an internet-facing server open. Inside were victim data, intrusion tools, shell history and the attacker’s own Cursor conversations. The logs show what AI-assisted ransomware actually looks like: fast, iterative and still directed by a skilled human.
CloudSEK traced the exposed infrastructure to a Russian-speaking affiliate active between April and July 2026. The wider operation compromised more than 20 organisations across nine countries and achieved domain-level or interactive access at 17. Recovered chat logs show Cursor Agent, running Anthropic’s Claude Sonnet, being used interactively against at least ten organisations.
The evidence came from the attacker’s own server
This was not an inference based only on polished malware or AI-style comments. Researchers found a misconfigured server containing Kerberos tickets, SAM and LSA credential extracts, BloodHound collections, Group Policy exports, command history, private repositories, Windows and Linux ransomware binaries, and the operator’s Cursor sessions.
Gambit Security independently analysed the same exposed infrastructure. Its telemetry corroborated that Cursor was invoked against live victim networks rather than being used only to write tools offline. The operator supplied credentials or an existing foothold, then asked the agent to perform work inside the compromised environment.
Cursor became an interactive intrusion assistant
The recovered instructions were written in Russian and covered the middle of the attack chain. Tasks included configuring tunnels, scanning internal networks with Nmap and NetExec, enumerating Active Directory, identifying privileged accounts, attempting NTLM relay attacks and testing certificate-based escalation paths with Certipy.
The operator also imposed explicit safety rules. Cursor was told not to perform DCSync and not to lock compromised credentials. Those instructions reveal human judgement about detection risk and operational consequences. The agent was not selecting targets or defining the campaign by itself.
Cloud Security Alliance says most AI-issued commands failed on their first attempt and needed manual refinement. That is a crucial limitation. Cursor accelerated syntax, troubleshooting and repeatable execution, but an experienced operator remained in the loop to interpret results and decide what happened next.
The AI-assisted activity was only part of the operation
The broader Aurora toolkit carried the intrusion from access toward theft and encryption. CloudSEK found 7-Zip archives split into 50-gigabyte chunks, S3-compatible exfiltration through s5cmd, SQL Server xp_cmdshell abuse and GodPotato privilege escalation.
The ransomware itself was written in Zig, with related Windows and Linux or ESXi variants. The ESXi build force-stopped virtual machines to release file locks before encrypting their files. It then replaced the SSH login banner with payment instructions instead of leaving a conventional ransom note.
Why this changes the defensive calculation
The breakthrough is not autonomous ransomware. It is the compression of specialist tasks into an interactive session. One operator can feed reconnaissance results into a coding agent, ask for the next command, paste back the error and keep moving without stopping to research every tool or protocol.
That does not eliminate the expertise barrier, but it lowers the cost of repeating known tradecraft. Techniques documented in public reports can be converted into working commands and adapted to a victim environment much faster than a static playbook.
What defenders should do now
- Detect unusual use of Cursor, Claude-enabled development tools and other coding agents on administrative systems. Treat their shell and network capabilities as privileged tooling.
- Monitor for Nmap, NetExec, BloodHound, Certipy, proxychains and tunnelling activity outside approved security workflows.
- Harden Active Directory Certificate Services, NTLM relay paths and privileged account enrollment before an attacker can automate the assessment.
- Correlate directory enumeration, service-ticket requests, remote administration and certificate enrollment instead of reviewing each signal in isolation.
- Restrict developer and administrator egress, especially connections that establish tunnels or move large archives to object-storage services.
- Retain command-line, PowerShell, LDAP, SMB and identity telemetry long enough to reconstruct a multi-week intrusion.
The bigger lesson
AI did not replace the ransomware operator. It gave the operator a responsive technical assistant inside the attack loop. Defenders should plan for adversaries who can troubleshoot faster, reuse complex procedures more consistently and turn yesterday’s research into tomorrow’s command sequence.
Sources: CloudSEK’s Aurora investigation and Cloud Security Alliance’s analysis.


