Monday, September 14, 2026

Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks

Aurora ransomware operators have been observed using Cursor Agent, powered by Claude Sonnet, to support hands-on intrusion activity across ten victim organizations, while deploying a purpose-built Linux encryptor designed to disrupt VMware ESXi environments.

The findings show how ransomware affiliates are integrating agentic AI into established post-compromise workflows rather than relying on it as a standalone attack capability.

The exposed environment provided visibility into the actor’s tooling, attack workflow, and an ESXi-capable ransomware sample named encrypt.out, with SHA-256 a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe.

Between April 8 and May 21, 2026, the Aurora operator used Cursor Agent with claude-4.5-sonnet-thinking in multiple victim environments.

The actor supplied the agent with valid credentials or an existing route, including SOCKS-based access, then instructed it to carry out reconnaissance, privilege assessment, internal scanning, and exploitation tasks.

The recovered sessions indicate that the operator used AI as an iterative technical assistant. In some cases, the attacker asked broad questions, such as identifying a user’s effective privileges.

In others, the operator directed the agent to use specific offensive tools or follow a prebuilt attack plan.

The agent often needed multiple command revisions before a task succeeded, underscoring that the human operator remained in control of execution and decision-making.

Observed tasks included deploying VPN clients and ProxyChains, scanning internal networks with Nmap and NetExec, collecting Active Directory information with BloodHound.

Attempting NTLM relay attacks with PetitPotam, Coerce Plus and PrinterBug, and conducting Active Directory Certificate Services attacks through Certipy.

The operator repeatedly instructed the AI not to perform DCSync, avoid account lockouts, and refrain from adding computer objects to the domain operational constraints apparently intended to reduce detection risk and prevent disruptive changes before encryption.

Aurora’s Linux payload was hosted on Cloudflare R2 and manually copied to internal victim hosts. The malware encrypts data in place using ChaCha20 and encrypts each session key with an embedded RSA-4096 public key.

Its command-line options support partial encryption, file-size limits, worker-thread control, folder targeting, and a dedicated -esxi mode.


Abuse of Cursor Agent (Source : Gambit).
Abuse of Cursor Agent (Source : Gambit).

Gambit Security’s Threat Intelligence team uncovered Cursor, exposed infrastructure linked to the Aurora operation, which has been active since about April 2026 and operates a public data-leak site.

Cursor AI-Powered Ransomware

When executed with the ESXi option, encrypt.out runs esxcli vm process list to enumerate active guest virtual machines and obtain their World IDs.

NetExec driven LDAP and SMB discovery, password policy retrieval, ASREPRoasting, Kerberoasting the same sequence, the same output file naming convention, every time.

Enumeration (Source : Gambit).
Enumeration (Source : Gambit).

It then force-terminates each guest through esxcli vm process kill –type=force –world-id=<world-id>, releasing locks on virtual disk files before encrypting them. Targeted files include VMDK, VMX, VMSD, VMSN, NVRAM, VMEM, VSWP and log files.

Notably, the malware avoids ESXi system volumes such as BOOTBANK* and OSDATA*. That choice leaves the hypervisor bootable, enabling administrators to access the host and encounter the extortion demand after the virtual machines have been taken offline.

Aurora writes the ransom message to /etc/ssh/sshd-banner, presenting it to administrators before the SSH login prompt.

The group also used esxi_finder.py, a custom NetExec LDAP module, to discover ESXi and vCenter infrastructure.

The module identifies internal subnets through Active Directory or an operator-provided range list, scans ports 443 and 902, examines TLS certificates for ESXi signatures, and queries /sdk, /ui/, and root paths to fingerprint the VMware product and determine exact build versions.

Separate research by CloudSEK linked an exposed directory to a Russian-speaking Aurora affiliate active against more than 20 organizations across nine countries from April through July.


Targeting and Victimology (Source : Gambit).
Targeting and Victimology (Source : Gambit).

The directory held credential material, Kerberos tickets, shell history, Cursor chat logs, custom NetExec modules, and Windows and Linux Aurora lockers compiled from a shared Zig codebase. Four recorded victims later appeared on Aurora’s leak site.

CloudSEK and TRM Labs also traced a settled victim payment through shared laundering infrastructure, identifying two confirmed Aurora victim payments and two additional flows consistent with separate victims.

The evidence supports the assessment that the actor operated as a direct ransomware affiliate, progressing from access and domain compromise to data theft, encryption, and extortion rather than simply brokering network access.

The campaign highlights the need to treat ESXi platforms, Active Directory Certificate Services, backup infrastructure, and remote administration paths as high-priority ransomware exposure points.

Organizations should isolate management networks, restrict SSH and ESXi access, monitor esxcli vm process kill activity, enforce SMB signing and Extended Protection for Authentication, and audit AD CS templates for ESC1, ESC6, and ESC8 misconfigurations.

Aurora’s operational model also reinforces a broader concern: AI agents can lower the time and skill required for iterative post-exploitation, but they do not eliminate the need for stolen credentials, valid access paths, and traditional offensive tooling.

In this case, the AI component accelerated an already mature ransomware workflow built around Active Directory compromise, lateral movement, data theft, and virtualization-layer disruption.

IOCs

TypeIOCNote
IP172.86.113.245c2
IP172.86.90.75c2
IP89.106.83.49SOCKS proxy
IP104.194.134.167SOCKS proxy
IP68.210.224.231SOCKS proxy
IndicatorTypeValue
Aurora Tor Negotiation SiteOnion Addressijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion
sap.exe (Windows locker)SHA-256eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207
encrypt.out (Linux/ESXi locker)SHA-256a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe
Ransom NoteFilename!!!README!!!DO_NOT_DELETE.txt
Operator VPSIPv4172.86.113.245
Operator VPSIPv4172.86.90.75

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a...

Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users

A Casbaneiro banking Trojan campaign targeting users across Latin...

AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process

A five-stage AsyncRAT campaign that chains a socially engineered...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

Related Articles

Recent News