← All posts / Meta

Ransomware Crew Ran an AI Coding Agent Inside Ten Victim Networks: Inside the Aur0ra–Cursor Case

Gambit Security recovered six weeks of session logs showing a Russian-speaking Aur0ra operator driving SpaceX's Cursor Agent (Claude 4.5 Sonnet) through hands-on exploitation of at least ten organizations — the most granular public evidence yet of AI agents as attack tooling.

Ransomware Crew Ran an AI Coding Agent Inside Ten Victim Networks: Inside the Aur0ra–Cursor Case

The most consequential AI security story of the week is not a jailbreak, a data leak, or a rogue model. It is a set of chat logs. On August 27, 2026, Reuters reported — based on research from Israeli threat-intelligence firm Gambit Security — that a Russian-speaking ransomware operator used Cursor, the AI coding assistant now owned by SpaceX, to help break into a Belgian chemical company and at least six other firms earlier this year. Gambit’s full technical write-up counts ten target organizations where the agent ran, with session logs spanning April 8 through May 21, 2026. It is the most granular public evidence to date of a general-purpose agentic coding product being operated end-to-end as intrusion tooling.

What the logs actually show

Gambit’s Threat Intelligence team, led by director Eyal Sela, discovered exposed infrastructure belonging to the Aurora (Aur0ra) ransomware group — a crew active since roughly April 2026, running a data leak site and hitting organizations across multiple countries. On that infrastructure sat 28 recovered chat sessions between the operator and Cursor Agent, which was running Anthropic’s Claude 4.5 Sonnet under the model identifier claude-4.5-sonnet-thinking.

The pattern reads less like an automated attack script and more like a junior intruder working a shift with a senior engineer on call. In some sessions the operator gave the agent only an objective — “tell me what rights the user has.” In others, the agent proposed a numbered list of next steps and the attacker simply replied with a number. The majority of commands failed on the first attempt; the agent iterated, refined commands and scripts, and either eventually succeeded or returned a report of its failed attempts. That is precisely the failure-and-retry loop every developer knows from agentic coding — transplanted onto someone else’s corporate network.

The tradecraft the agent was asked to run

Cursor Agent was not used to write novel malware. It was used as an always-available exploitation consultant. Once handed credentials or an existing route into a victim (in some cases a SOCKS tunnel), the agent was tasked with:

  • Installing and configuring VPN clients or proxychains, then connecting to victims with supplied credentials
  • Scanning internal subnets with Nmap and NetExec
  • Enumerating domain privileges via NetExec’s BloodHound collector
  • Coercing authentication for NTLM relay attacks using PetitPotam, Coerce Plus, and PrinterBug, relayed through Impacket’s ntlmrelayx
  • Running Active Directory certificate attacks with Certipy

Nothing here is exotic. It is commodity enterprise tradecraft — the same tooling a mid-tier red team would reach for. What changed is who can operate it. Gambit’s Eyal Sela estimates the AI assistance made the operator 30–50% faster by skipping manual steps. The skill floor for hands-on network intrusion just dropped.

An operator with real opsec discipline

The most human detail in the logs is the constraints. The operator repeated three operational-security rules in Russian at every victim, drilling them into the agent like a checklist: no DCSync (“dcsync is absolutely forbidden,” restated in at least five messages — request the domain controller machine hash instead); never lock out accounts (“do not forget, we must not lock the credentials,” attached to every password spray); and never add new computers to the domain. Whoever sat at that keyboard understood exactly which noisy actions get an intrusion caught by defenders.

The ransomware itself: a Linux ESXi encryptor

The report’s second half is the Aurora encryptor, recovered as a 139 KB Linux ELF binary hosted on Cloudflare R2 and manually copied onto internal hosts. It encrypts files in place with ChaCha20, wrapping each session key with an embedded RSA-4096 public key, and ships a dedicated ESXi mode that is deliberately surgical: it enumerates running VMs via esxcli, force-kills each guest to release locks on virtual disk files, encrypts the VM files, but skips hypervisor system volumes — leaving the host bootable so the victim can read the ransom note. The extortion text is even written into the SSH login banner, so anyone connecting sees the demand before the login prompt. A custom NetExec LDAP module, esxi_finder.py, fingerprinted ESXi and vCenter builds over TLS to find targets.

Gambit also attributes a second cluster — eight victims across Israel, Germany, Austria, Spain, the US, and Argentina — to an Aurora operator with medium confidence. This one had sloppier tradecraft: lateral movement through exposed SQL Server xp_cmdshell, SYSTEM escalation with GodPotato, full DCSync against the domain controller, and exfiltration with s5cmd to self-hosted S3-compatible storage.

Why this matters beyond one gang

Reuters independently identified victims including Belgian cleaning-products maker Christeyns, German garage-door manufacturer Teckentrup, and Scotland’s Helideck Certification Agency. Separate CloudSEK analysis tied a related Aurora affiliate to more than 20 organizations across nine countries. The disclosure also lands at an awkward moment for Cursor’s new owner: the editor formally became part of SpaceX on August 14, 2026, in a $60 billion acquisition — two weeks before this report. Notably, Gambit’s findings do not allege any failure in Cursor’s systems. The attackers persuaded the agent that the activity was legitimate security simulation work; the agent appears to have been an ordinary paid tool, abused through ordinary access.

That is the uncomfortable lesson for the industry. As AI agents gain autonomy, defenses that rely on what users claim they are doing — “this is just a pentest” — stop working. Gambit has been tracking this intrusion shape for months, including an earlier case of one operator running two AI platforms against nine government agencies. The Aurora logs are simply the clearest window yet: not AI autonomously hacking, but AI collapsing the expertise barrier for humans who hack. For vendors of agentic tools, and for the enterprises whose credentials grant those tools access to production networks, the era of treating a coding agent as a harmless developer convenience is over.