Aurora Used Cursor to Turn Ransomware Into a Repeatable Playbook

Recovered Cursor logs show an Aurora ransomware affiliate using Claude against live victim networks while a skilled human controlled the intrusion.

Recovered Cursor logs show an Aurora ransomware affiliate using Claude against live victim networks while a skilled human controlled the intrusion.

A fake verification prompt led to DLL sideloading, Active Directory reconnaissance and a reverse tunnel that turned one Windows endpoint into an internal network pivot.

KerberLoss can disrupt Kerberos services. ResetNightmare can turn a directory write permission into a privileged password reset and domain takeover.

Hundreds of AI agents exploited PaperCut at 395 organisations, with some intrusions reaching domain administrator in minutes. Defenders must investigate Active Directory, not only the PaperCut host.

Choose a safe Active Directory DNS namespace using a registered domain, internal subdomain, verified UPN suffix and current Microsoft guidance.