Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
AI Summary
Aurora ransomware operators, a Russian-speaking cybercrime group, have been leveraging SpaceX's AI-powered coding assistant Cursor to plan and execute attacks against at least 10 organizations between April and May 2026. The group used Cursor to assist in attack planning, including Active Directory Certificate Services exploitation, and conducted hands-on exploitation using credentials or existing access. The attack chain includes initial access via email bombing and social engineering, lateral movement using SMB, LDAP, RDP, and RPC, privilege escalation, evasion of security tools, data exfiltration, and deployment of a multi-platform encryptor written in Zig. A related AI-assisted toolkit called Gryxa has also emerged, enabling persistent access, credential theft from Chromium browsers, and evasion of endpoint protection.
AI-extracted · verify before operational use