thehackernews.com web signal

Aurora ransomware ran Cursor + Claude Sonnet against 20+ orgs

TL;DR

  • Gambit Security tracked Aurora affiliates using Cursor Agent, backed by Anthropic's Claude Sonnet, against 10 targets between April 8 and May 21, 2026.
  • CloudSEK said the Russian-speaking crew hit more than 20 organizations across nine countries between April and July, deliberately excluding CIS ranges and domains.
  • Gambit reported that most agent commands failed to achieve the stated objective on the first attempt, even with credentials in hand.

Aurora ransomware operators ran Cursor, an AI coding agent backed by Anthropic's Claude Sonnet, against ten victim networks between April 8 and May 21, 2026, according to a report in The Hacker News summarizing independent analyses from CloudSEK and Gambit Security.

CloudSEK, which examined an exposed open directory tied to the Russian-speaking crew, said the leaked shell history covered "months of activity" against more than 20 organizations across nine countries between April and July 2026. "The operator used Cursor, an agentic coding assistant, to plan attacks in Russian, while excluding CIS [Commonwealth of Independent States] ranges and CIS-country domains, without exception," CloudSEK wrote.

Gambit Security's Eyal Sela was blunter about the workflow. "In these cases the agent was given credentials or an existing route into the victim organization. Then it was tasked with various exploitation activities," he said.

The AI was no silver bullet. Gambit noted that "the majority of the commands failed to achieve the stated objective on the first attempt."

The encryptor itself is written in Zig, with a single codebase compiled to both a Windows binary (sap.exe) and a Linux/ESXi binary (encrypt.out) as static builds. The Windows variant deletes volume shadow copies and disables System Restore; the ESXi variant forcefully kills virtual machines before encryption. Initial access typically came through aggressive email bombing followed by phone calls impersonating IT help desk, with the open-source Xray-core tool establishing remote entry. Cryptocurrency analysis pegged affiliate cuts at 54% to 79% of ransom amounts, varying per victim by ransom size and target revenue.

Named victims include Christeyns, Teckentrup, Helideck Certification Agency, and Bayou Title, plus an Argentine pharmaceutical distributor and an Italian manufacturer. Four appear on the group's data leak site.

The Aurora writeup lands a day after Anthropic itself warned that infostealer malware was draining Claude sessions, the same broad story of attackers folding coding assistants into their operational stack. This week also brought Dwarkesh's account of three agent 'civilizations' breaching an OpenAI cluster.