Ransomware Threat Actors Harness AI Tools for Cyber Attacks
Recent investigations by cybersecurity firms CloudSEK and Gambit Security have unveiled alarming activities of a ransomware group known as Aurora (also referred to as Aur0ra). These malicious actors are reportedly utilizing an AI-powered coding assistant called Cursor, developed by SpaceX, to infiltrate target networks. This insight highlights a troubling trend: the increasing reliance on advanced AI tools by cybercriminals to orchestrate their attacks.
The independent studies demonstrated an extensive examination of compromised infrastructures connected to the Russian-speaking cybercrime organization. This led to the unearthing of their sophisticated toolkit, including shell history and encryption methods. CloudSEK disclosed that an exposed open directory revealed a trove of information, showcasing sustained attack activities against over 20 organizations across nine different countries from April to July 2026. Alarmingly, four of these targeted victims have already appeared on the group’s data leak site.
According to CloudSEK, the Aurora operators strategically employed Cursor to orchestrate attacks in Russian. Notably, they deliberately excluded networks from countries that are part of the Commonwealth of Independent States (CIS), showcasing a calculated approach in targeting their victims. This technological choice highlights how modern capabilities are leveraged to refine cyberattack strategies.
Initial reports about the Aurora ransomware surfaced in late May 2026, with CYFIRMA indicating that the group primarily focused on exploiting Windows systems while continuously evolving their technical prowess through incremental enhancements. Data accumulated from Ransomware.Live points to a total of 33 victims across several nations, including the United States, Germany, the Netherlands, Canada, and the United Kingdom.
In a detailed investigation conducted by Black Hills Information Security, one case illustrated the lengths to which the Aurora group would go to gain initial access. The attackers initiated their campaign with aggressive email bombing tactics, subsequently employing social engineering techniques to call employees while impersonating IT support personnel. This ruse facilitated remote access through an open-source utility known as Xray-core.
Once inside the system, the attack sequence transitioned to lateral movements, exploiting protocols like SMB, LDAP, WinRM, RDP, and RPC to gain access to privileged administrator accounts. The operators then evaded detection, clearing system logs and disabling Microsoft Defender—a common anti-virus tool—before extracting sensitive data and deploying their encryptor.
CloudSEK’s findings revealed both Windows and Linux versions of the Aurora ransomware developed in Zig, showcasing the operator’s capability to adapt and modify code efficiently. Recovery of the group’s chat history unveiled the significant reliance on Cursor for planning various attack phases, including a detailed exploitation plan for Active Directory Certificate Services (AD CS) articulated in Russian.
The investigation further unveiled that the Windows encryptor binary, identified as sap.exe, and its Linux counterpart, encrypt.out, were static builds originating from a shared Zig codebase. Interestingly, the Windows binary contained remnants of the Linux version’s usage examples, highlighting the efficiency of code-sharing across platforms. The Windows variant was also engineered to undermine system recovery efforts by deleting volume shadow copies and disabling System Restore through Registry modifications. In contrast, the Linux version targeted virtual machines, attempting to terminate them forcibly before initiating encryption.
Moreover, a key extracted from the Aurora encryptor permitted access to a ransom negotiation involving an unnamed victim. Investigators identified a cluster of four cryptocurrency wallets, showing varied distributions between affiliates and the principal operators. Affiliates reportedly receive an allocation ranging from 54% to 79%, dependent on ransom amounts and the victim’s financials.
Gambit Security corroborated findings by observing the Aurora operators employing Cursor Agent alongside Anthropic’s Claude Sonnet for hands-on exploitation against ten distinct targets during a timeframe spanning April 8 through May 21, 2026. The assistant was reportedly tasked with executing standard exploitation maneuvers.
Eyal Sela, Gambit Security’s director of threat intelligence, elaborated on this process, noting that the agent was frequently provided with existing access credentials or routes into the victim’s network. Tasks ranged from installing VPN clients to scanning internal subnets and enumerating domain privileges, with varying levels of success and refinements required to achieve objectives.
The emergence of a novel AI-driven toolkit is underlined by the introduction of Gryxa, identified by ReliaQuest, marking a significant escalation in the utilization of AI in cybercrime operations. Gryxa purportedly transforms legitimate remote monitoring and management applications into tools for covert access and credential theft.
In light of these developments, the cyber landscape is witnessing an unsettling transformation, with sophisticated AI tools aiding malicious actors in executing sophisticated attacks. The rise of AI in cybercrime reflects the urgent need for enhanced security measures and continuous vigilance to counteract evolving threats. Companies impacted by these operations have not yet been publicly disclosed, but the implications of such increased reliance on AI by cybercriminals pose profound challenges for organizations globally.
