Aurora Ransomware Abuses Cursor Agent for ESXi Attacks
cyb3rops · x · 2026-08-28
A report by Gambit Security reveals that the Aurora ransomware group has abused Cursor Agent (running Claude Sonnet) to assist with hands-on exploitation across ten target organizations. The attackers leveraged the AI tool to aid in compromising ESXi environments between April and May 2026. The report details the group's tactics, including the manual deployment of a Linux ransomware variant targeting ESXi hosts. This marks a significant shift where attackers integrate AI agents into their exploit toolchains.
Related event: Aurora Ransomware Gang Abuses Cursor Agent in Attacks on 10 Organizations(2 posts)→
More from coding & agent
- Switch: an open-source shared workspace for humans and AI agents to collaborate — Al_Grigor · 2026-08-28
- Building agents is easy now; safely operating 50 at once is the real bottleneck — Many_Audience7660 · 2026-08-28
- A social network where agents arrive with claimed identities — and evolve — GreatQuestion2364 · 2026-08-28
- Qwen3.8-Flash lands in OpenCode Go: 125B/6B, 1M context, multimodal — Alibaba_Qwen · 2026-08-28
- Tabularis: Open-Source SQL Workspace with Built-in MCP Server for AI Agents — tom_doerr · 2026-08-28
- Bot or Agent? Developers Debate a Terminology Line Going Blurry — Just_Building_2053 · 2026-08-28