Cyber Security News

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation.

The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow.

It contained victim-specific directories, shell history, Kerberos tickets, credential dumps, Group Policy exports, BloodHound collections, custom tools, Cursor chat logs, and Aurora ransomware binaries.

CloudSEK said the evidence indicates that the actor was directly conducting intrusions, theft, encryption, and extortion rather than selling network access to another ransomware operator.

The operator achieved domain-level or interactive access in at least 17 environments. Four victims were subsequently named on Aurora’s public leak site.

At the same time, other affected organizations were reportedly notified through national CERTs or direct coordinated disclosure before publication.

The victims spanned manufacturing, food and agriculture, professional services, transport and logistics, consumer goods, waste management, and IT or backup infrastructure. Manufacturing represented the largest affected sector.

The affiliate used Cursor, an agentic coding assistant, to draft and reason through attack sequences in Russian.

Recovered chat logs reportedly included a detailed Active Directory Certificate Services exploitation plan, demonstrating sustained interaction with the tool during one of the actor’s most active victim engagements.

Enumeration (Source : CloudSEK).

The finding does not indicate that Cursor independently performed intrusions. Instead, it illustrates how threat actors can use general-purpose AI tools to accelerate reconnaissance planning, sequence established attack methods, troubleshoot scripts, and document complex enterprise attack paths.

In this case, the AI-assisted workflow appeared alongside a mature arsenal of publicly available and custom offensive tooling.

The operator consistently avoided CIS-country domains and IP ranges across target lists, scans, and success logs, an operational pattern often associated with Russian-speaking cybercrime actors.

CloudSEK assessed with high confidence that the individual behind the activity was Russian-speaking.

The affiliate used NetExec for LDAP and SMB discovery, including password-policy checks, AS-REP roasting, Kerberoasting, and domain enumeration.

CloudSEK Researchers said that, the activity came to light after researchers discovered the attacker’s Linux home directory exposed through an unauthenticated file listing on port 8888.

Ransomware Hacker Uses AI

The activity then moved into privilege escalation through custom noPac tooling, ADCS abuse, and NTLM relay chains involving PetitPotam, PrinterBug, and DFSCoerce.

Researchers found activity tied to ADCS ESC1, ESC6, and ESC8 abuse paths misconfigurations that can enable attackers to obtain high-privilege certificates or relay NTLM authentication to vulnerable certificate enrollment services.

In at least one target environment, the actor pursued template misconfigurations capable of issuing a domain administrator certificate.

For data theft, the operator used PowerShell to archive material into 50 GB chunks before staging and retrieving it.

The presence of backup-system credentials, Azure AD Connect account hashes, krbtgt material, privileged Kerberos tickets, SAP/ERP enumeration, and TLS private keys highlights the depth of access achieved in selected compromises.

The exposed directory contained Windows and Linux/ESXi variants of the Aurora encryptor, written entirely in Zig a relatively uncommon language for ransomware development.

Targeted countries (Source : CloudSEK).

The binaries were static builds from a shared codebase and were hosted in a public Cloudflare R2 bucket before being transferred to staging systems through SCP.

The Windows payload attempted to impede recovery by enabling backup privileges, deleting Volume Shadow Copies, resizing shadow storage, disabling System Restore, and checking for Hyper-V management services.

The Linux/ESXi version enumerated running virtual machines, force-stopped them, encrypted virtual-machine-related files, and wrote the ransom message to the ESXi host’s SSH login banner.

Access to Extortion (Source : CloudSEK).

A key recovered from the encryptor gave CloudSEK access to a completed ransom negotiation. In collaboration with TRM Labs, the researchers traced the payment and identified two confirmed victim payments plus two additional transactions consistent with distinct Aurora victims.

The payments converged through shared laundering infrastructure, suggesting an established cash-out network rather than isolated wallets.

Payment splits ranged from 35/65 to 46/54, with no fixed affiliate share. That variability suggests Aurora’s affiliate compensation may be negotiated per victim, potentially based on ransom size or victim characteristics.

The investigation offers rare evidence that this affiliate was involved end-to-end from AI-supported planning and domain compromise to ransomware deployment and profit collection.

IOCs

IndicatorTypeValue
Aurora Tor Negotiation SiteOnion Addressijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion
sap.exe (Windows locker)SHA-256eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207
encrypt.out (Linux/ESXi locker)SHA-256a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe
Ransom NoteFilename!!!README!!!DO_NOT_DELETE.txt
Operator VPSIPv4172.86.113.245
Operator VPSIPv4172.86.90.75
Operator VPSIPv4144.172.116.150
Operator VPS (SOCKS relay)IPv4104.194.134.167

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix…

10 minutes ago

Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power

AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways,…

13 minutes ago

TP-Link Kasa Smart Home Flaw Lets Attackers Forge Control Messages and Take Control of Devices

TP-Link has revealed a critical vulnerability in Kasa smart home devices that could allow an…

25 minutes ago

CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068, a remote code execution…

1 hour ago

FBI Seizes China State-Sponsored Hacker Platforms Used to Target U.S. Critical Infrastructure

The U.S. Justice Department and the FBI have seized domains associated with two hacking platforms…

2 hours ago

AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale

Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today announced the launch of AgentZ,…

2 hours ago