Aurora Ransomware Abuses Cursor Agent for ESXi Attacks

cyb3rops · x · 2026-08-28

A report by Gambit Security reveals that the Aurora ransomware group has abused Cursor Agent (running Claude Sonnet) to assist with hands-on exploitation across ten target organizations. The attackers leveraged the AI tool to aid in compromising ESXi environments between April and May 2026. The report details the group's tactics, including the manual deployment of a Linux ransomware variant targeting ESXi hosts. This marks a significant shift where attackers integrate AI agents into their exploit toolchains.

Related event: Aurora Ransomware Gang Abuses Cursor Agent in Attacks on 10 Organizations(2 posts)→

Original post →

More from coding & agent

coding & agent channel →