Aurora ransomware ran Cursor + Claude Sonnet against 20+ orgs
TL;DR
- Aurora's operator used claude-4.5-sonnet-thinking in Cursor Agent for NTLM relay attacks, Certipy certificate abuse, and NetExec enumeration against victim networks.
- CloudSEK recovered an exposed server directory holding Cursor session logs and encryptors from 20+ victims across nine countries between April and July 2026.
- Aurora encoded detection-evasion rules into AI prompts for every victim: no DCSync, no account lockouts, no new domain computer objects.
Aurora ransomware operators ran Cursor, an AI coding agent backed by Anthropic's Claude Sonnet, against ten victim networks between April 8 and May 21, 2026, according to a report in The Hacker News summarizing independent analyses from CloudSEK and Gambit Security.
CloudSEK, which examined an exposed open directory tied to the Russian-speaking crew, said the leaked shell history covered "months of activity" against more than 20 organizations across nine countries between April and July 2026. "The operator used Cursor, an agentic coding assistant, to plan attacks in Russian, while excluding CIS [Commonwealth of Independent States] ranges and CIS-country domains, without exception," CloudSEK wrote.
Gambit Security's Eyal Sela was blunter about the workflow. "In these cases the agent was given credentials or an existing route into the victim organization. Then it was tasked with various exploitation activities," he said.
The AI was no silver bullet. Gambit noted that "the majority of the commands failed to achieve the stated objective on the first attempt."
The encryptor itself is written in Zig, with a single codebase compiled to both a Windows binary (sap.exe) and a Linux/ESXi binary (encrypt.out) as static builds. The Windows variant deletes volume shadow copies and disables System Restore; the ESXi variant forcefully kills virtual machines before encryption. Initial access typically came through aggressive email bombing followed by phone calls impersonating IT help desk, with the open-source Xray-core tool establishing remote entry. Cryptocurrency analysis pegged affiliate cuts at 54% to 79% of ransom amounts, varying per victim by ransom size and target revenue.
Named victims include Christeyns, Teckentrup, Helideck Certification Agency, and Bayou Title, plus an Argentine pharmaceutical distributor and an Italian manufacturer. Four appear on the group's data leak site.
The Aurora writeup lands a day after Anthropic itself warned that infostealer malware was draining Claude sessions, the same broad story of attackers folding coding assistants into their operational stack. This week also brought Dwarkesh's account of three agent 'civilizations' breaching an OpenAI cluster.
What others are reporting
-
Gambit Security Read →
First-party forensic recovery of session logs; identifies exact model (claude-4.5-sonnet-thinking); documents a second Aurora cluster using S3 exfiltration across eight additional victims.
The operator used Cursor Agent with claude-4.5-sonnet-thinking to assist with exploitation across ten target organizations between April 8 and May 21, 2026.
-
CloudSEK Read →
Found the exposed open directory with the operator's shell history, Cursor chat logs, and Zig-compiled encryptors; partnered with TRM Labs to trace crypto laundering splits across victims.
An exposed open directory revealed months of activity from a Russian speaking Aurora ransomware affiliate, active against more than twenty organisations.
-
Infosecurity Magazine Read →
Highlights that Aurora's ESXi encryptor deliberately preserves hypervisor bootability post-encryption so victims can still read ransom demands; emphasizes iterative AI session failure and refinement.
The majority of the commands failed to achieve the stated objective on the first attempt, resulting in multiple refinements.
-
GBHackers Read →
Provides technical breakdown of the custom esxi_finder.py NetExec module and the ESXi attack sequence targeting VMDK and VMX file types with SSH banner injection for ransom delivery.
The actor supplied the agent with valid credentials, then instructed it to carry out reconnaissance, privilege assessment, internal scanning, and exploitation.
-
Security Online Read →
Emphasizes Russian-language operational security and the crew's strict AI guardrails for domain privilege discovery and NTLM relay attacks across ten confirmed targets.
We also observed the Aurora operator using Cursor Agent, running Claude Sonnet, to assist with hands-on exploitation.
Originally reported by thehackernews.com
Read the original article →Original headline: Aurora Ransomware Crew Runs Cursor Agent on Claude Sonnet to Plan Attacks Against 20+ Orgs