Aurora Ransomware Affiliate Uses Cursor AI to Plan Attacks Against 20+ Organizations

An exposed open directory has revealed months of activity linked to a Russian-speaking affiliate of the Aurora ransomware operation.

CloudSEK said the operator targeted more than 20 organizations across nine countries between April and July 2026, gaining domain-level or interactive access at 17 victims.

The unprotected Linux home directory was reportedly served through a file listing on port 8888. It contained victim folders, Kerberos tickets, credential dumps, Active Directory data, shell-history files, Cursor AI chat logs, exploit tools, and Aurora ransomware binaries.

Four organizations documented in the files were later listed on Aurora’s public leak site. CloudSEK assessed with high confidence that the actor was an Aurora affiliate conducting intrusions directly, rather than an initial-access broker selling access to other criminals.

The operator reportedly used rented SOCKS proxy infrastructure, mainly VPS servers in Germany and the United States, to hide direct connections to victim environments.

Aurora Uses Cursor AI

The recovered records show the affiliate used Cursor, an AI coding assistant, to plan attacks in Russian.

The chats included sustained discussions of Active Directory Certificate Services abuse and other domain-compromise paths during an engagement involving multiple victims.

The most heavily-worked AI-assisted engagement in the operator's recovered chat history (Source: cloudsek)
The most heavily-worked AI-assisted engagement in the operator’s recovered chat history (Source: cloudsek)

The attacker followed a repeatable playbook across targets. It used NetExec for LDAP and SMB discovery, password-policy checks, ASREPRoasting, Kerberoasting, BloodHound collection, and credential validation.

For escalation, the affiliate maintained custom scripts for the noPac attack chain and used ADCS weaknesses associated with ESC1, ESC6, and ESC8. The toolkit also included NTLM-relay methods involving PetitPotam, PrinterBug, and DFSCoerce.

CloudSEK said the operator archived stolen data using PowerShell-driven 7-Zip jobs, splitting material into 50 GB chunks before staging and extracting it.

Browser credential theft, VPN credential validation, backup-system access, Active Directory compromise, and ESXi discovery were also documented.

Investigators found Windows and Linux/ESXi versions of the Aurora encryptor in the directory. The binaries were written in Zig, an uncommon programming language for ransomware, and appeared to originate from a shared codebase.

The Windows payload, named sap.exe, includes anti-recovery capabilities that target volume shadow copies and System Restore.

Aurora Uses Cursor AI (Source: cloudsek)
Aurora Uses Cursor AI (Source: cloudsek)

The Linux/ESXi variant, encrypt.out, can identify and stop virtual machines before encrypting VM-related files. Instead of dropping a ransom note on ESXi, it reportedly modifies the SSH login banner to display the extortion message.

A key recovered from the encryptor also gave CloudSEK access to a completed ransom negotiation. In cooperation with TRM Labs, the researchers traced the associated Bitcoin payment and identified links to Aurora’s wider laundering network.

Indicators of Compromise

Indicator typeValueDescription
Aurora negotiation siteijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onionAurora ransomware Tor negotiation portal
Windows encryptorsap.exeAurora Windows ransomware pa

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories