
Aurora Ransomware Group Uses Cursor AI for AD CS Exploitation Plans in 10 Targets
Aurora ransomware operators integrated Cursor AI into active campaigns, producing detailed attack plans in Russian while maintaining strict geographic exclusions. Evidence from exposed infrastructure shows unified Zig encryptors and variable affiliate payouts. The pattern points to accelerating AI-assisted tooling in ransomware operations.
Exposed directories from the Russian-speaking group revealed months of activity logs, Zig-based encryptors for Windows and Linux/ESXi, and chat histories showing Cursor running Claude Sonnet. The operator planned attacks while explicitly excluding CIS IP ranges and domains. Recovered data included shell histories, an AD CS exploitation roadmap, and four crypto wallets splitting affiliate payments between 54% and 79%.
CloudSEK and Gambit Security independently confirmed the toolkit and Cursor usage against over 20 organizations in nine countries, with four victims later posted to the leak site. Initial access often involved email bombing followed by help-desk vishing via Xray-core. Post-compromise steps included SMB/LDAP/WinRM lateral movement, log clearing, Defender disablement, and volume shadow copy deletion.
The single Zig codebase compiled for multiple platforms and the static build artifacts indicate deliberate code reuse rather than separate development teams. Affiliate revenue splits varied by victim size, suggesting negotiated rather than fixed terms.
Next indicators to watch are new Cursor-generated scripts targeting AD CS or ESXi hosts and wallet activity spikes above $500k in single transactions within 60 days.
Gambit Security: Aurora will publish at least three new Cursor-generated exploit scripts against AD CS within 90 days.
Sources (3)
- [1]Primary Source(https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html)
- [2]Supporting Source(https://cloudsek.com/blog/aurora-ransomware-cursor-exposure)
- [3]Supporting Source(https://gambitsecurity.com/research/aurora-cursor-agent-analysis)