A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation.
The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow.
It contained victim-specific directories, shell history, Kerberos tickets, credential dumps, Group Policy exports, BloodHound collections, custom tools, Cursor chat logs, and Aurora ransomware binaries.
CloudSEK said the evidence indicates that the actor was directly conducting intrusions, theft, encryption, and extortion rather than selling network access to another ransomware operator.
The operator achieved domain-level or interactive access in at least 17 environments. Four victims were subsequently named on Aurora’s public leak site.
At the same time, other affected organizations were reportedly notified through national CERTs or direct coordinated disclosure before publication.
The victims spanned manufacturing, food and agriculture, professional services, transport and logistics, consumer goods, waste management, and IT or backup infrastructure. Manufacturing represented the largest affected sector.
The affiliate used Cursor, an agentic coding assistant, to draft and reason through attack sequences in Russian.
Recovered chat logs reportedly included a detailed Active Directory Certificate Services exploitation plan, demonstrating sustained interaction with the tool during one of the actor’s most active victim engagements.
The finding does not indicate that Cursor independently performed intrusions. Instead, it illustrates how threat actors can use general-purpose AI tools to accelerate reconnaissance planning, sequence established attack methods, troubleshoot scripts, and document complex enterprise attack paths.
In this case, the AI-assisted workflow appeared alongside a mature arsenal of publicly available and custom offensive tooling.
The operator consistently avoided CIS-country domains and IP ranges across target lists, scans, and success logs, an operational pattern often associated with Russian-speaking cybercrime actors.
CloudSEK assessed with high confidence that the individual behind the activity was Russian-speaking.
The affiliate used NetExec for LDAP and SMB discovery, including password-policy checks, AS-REP roasting, Kerberoasting, and domain enumeration.
CloudSEK Researchers said that, the activity came to light after researchers discovered the attacker’s Linux home directory exposed through an unauthenticated file listing on port 8888.
The activity then moved into privilege escalation through custom noPac tooling, ADCS abuse, and NTLM relay chains involving PetitPotam, PrinterBug, and DFSCoerce.
Researchers found activity tied to ADCS ESC1, ESC6, and ESC8 abuse paths misconfigurations that can enable attackers to obtain high-privilege certificates or relay NTLM authentication to vulnerable certificate enrollment services.
In at least one target environment, the actor pursued template misconfigurations capable of issuing a domain administrator certificate.
For data theft, the operator used PowerShell to archive material into 50 GB chunks before staging and retrieving it.
The presence of backup-system credentials, Azure AD Connect account hashes, krbtgt material, privileged Kerberos tickets, SAP/ERP enumeration, and TLS private keys highlights the depth of access achieved in selected compromises.
The exposed directory contained Windows and Linux/ESXi variants of the Aurora encryptor, written entirely in Zig a relatively uncommon language for ransomware development.
The binaries were static builds from a shared codebase and were hosted in a public Cloudflare R2 bucket before being transferred to staging systems through SCP.
The Windows payload attempted to impede recovery by enabling backup privileges, deleting Volume Shadow Copies, resizing shadow storage, disabling System Restore, and checking for Hyper-V management services.
The Linux/ESXi version enumerated running virtual machines, force-stopped them, encrypted virtual-machine-related files, and wrote the ransom message to the ESXi host’s SSH login banner.
A key recovered from the encryptor gave CloudSEK access to a completed ransom negotiation. In collaboration with TRM Labs, the researchers traced the payment and identified two confirmed victim payments plus two additional transactions consistent with distinct Aurora victims.
The payments converged through shared laundering infrastructure, suggesting an established cash-out network rather than isolated wallets.
Payment splits ranged from 35/65 to 46/54, with no fixed affiliate share. That variability suggests Aurora’s affiliate compensation may be negotiated per victim, potentially based on ransom size or victim characteristics.
The investigation offers rare evidence that this affiliate was involved end-to-end from AI-supported planning and domain compromise to ransomware deployment and profit collection.
| Indicator | Type | Value |
|---|---|---|
| Aurora Tor Negotiation Site | Onion Address | ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion |
| sap.exe (Windows locker) | SHA-256 | eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207 |
| encrypt.out (Linux/ESXi locker) | SHA-256 | a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe |
| Ransom Note | Filename | !!!README!!!DO_NOT_DELETE.txt |
| Operator VPS | IPv4 | 172.86.113.245 |
| Operator VPS | IPv4 | 172.86.90.75 |
| Operator VPS | IPv4 | 144.172.116.150 |
| Operator VPS (SOCKS relay) | IPv4 | 104.194.134.167 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix…
AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways,…
TP-Link has revealed a critical vulnerability in Kasa smart home devices that could allow an…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068, a remote code execution…
The U.S. Justice Department and the FBI have seized domains associated with two hacking platforms…
Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today announced the launch of AgentZ,…