Report: Aurora ransomware used Cursor Agent to help breach 10 organizations
cyb3rops · x · 2026-08-27
Gambit Security's Threat Intelligence team published a report on recent Aurora ransomware activity:
- The group has been active since around April 2026, running a data leak site and targeting organizations across multiple countries;
- Between April 8 and May 21, 2026, the operator used Cursor Agent running Claude Sonnet to assist with hands-on exploitation of ten target organizations;
- They deployed a Linux ransomware variant targeting ESXi environments (hosted on Cloudflare R2 and copied manually to internal hosts), encrypting files in place with ChaCha20 and wrapping session keys with embedded RSA-4096;
- A second activity cluster was attributed to an Aurora operator with medium confidence.
More from coding & agent
- LangChain Managed Deep Agents Support Environment Baking at Deploy — LangChain · 2026-08-27
- Why AI Agents Actually Need Memory? A Deep Dive into Technical Necessity — _jaydeepkarale · 2026-08-27
- ARK launches SDK to intercept bad tool decisions and enforce policies at runtime — Aromatic-Ad-6711 · 2026-08-27
- Agent Workforce Performance Depends on Setup — nikvassev · 2026-08-27
- Preventing Agents from Rewriting Contracts: A Three-Layer Architecture — haandol-_- · 2026-08-27
- Agent Autonomy Demo: Domain Bought Automatically Last Night — billyjhowell · 2026-08-27