AI Coding Assistant Now a Ransomware Weapon
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
Ransomware operators are adding an AI-powered coding assistant to their arsenal, using it to automate the dirty work of post-compromise exploitation. According to a new study from Gambit Security's Threat Intelligence team, actors behind the Aurora ransomware have been observed abusing Cursor Agent — an AI tool designed for software developers — to help run attacks against at least ten victims between April 8 and May 26, 2026. The findings, published August 27, point to a growing trend of threat actors experimenting with AI to speed up and refine their campaigns.
An AI Assistant for Intrusion
Cursor Agent is normally used by developers to complete complex coding tasks independently, execute terminal commands, and edit code. But the Aurora operators repurposed it for intrusion, handing the agent credentials or an existing foothold into victim networks. The tool then assisted with post-compromise activities, including reconnaissance, installing a VPN client, and running certificate attacks.
The research shows the AI did not always succeed at its assigned tasks. In fact, the majority of commands failed on the first attempt, requiring multiple rounds of refinement. But the fact that attackers are willing to iterate with AI tools indicates a shift toward automation in the exploitation phase, which could lower the barrier for less skilled cybercriminals.
Prompting the Agent for Intel
Some of the commands given to Cursor Agent were aimed at gathering intelligence about the victim's environment. In certain cases, the attacker simply asked for a stated objective, such as "tell me what rights the user has." In others, they gave specific instructions on which exploitation tools to use or to follow a previously generated attack plan.
Examples include enumerating the domain to report what privileges a supplied user holds, using NetExec's BloodHound collector, and scanning internal subnets for hosts with Nmap or NetExec. These are standard reconnaissance steps in a manual intrusion, but here they were delegated to an AI agent, which could execute them at scale and speed.
From Recon to Exploitation
The agent was also tasked with more direct exploitation activities. It attempted NTLM relay attacks by coercing authentication with tools like PetitPotam, Coerce Plus, and PrinterBug, and ran certificate attacks with Certipy. Additionally, Cursor Agent was told to install a VPN client or proxychains, then configure it and connect to the victim using supplied credentials or an existing SOCKS tunnel.
These activities are not new to ransomware operations, but the use of an AI agent to carry them out represents a notable evolution. Rather than manually typing commands, the operator can issue high-level instructions and let the AI figure out the details, potentially saving time and reducing the need for deep technical expertise.
Mostly Failed, Sometimes Succeeded
The Gambit researchers noted that the agent's performance was mixed. "The majority of the commands failed to achieve the stated objective on the first attempt, resulting in multiple refinements and changes to the commands and scripts used for each task. Some eventually succeeded in achieving the objective, while others failed and returned only a report of the attempts to the attacker," they wrote in the study.
This observation cuts both ways for defenders. On one hand, the AI's unreliability may limit its utility for attackers. On the other, the fact that operators are investing time in refining AI-generated commands suggests they see enough value to keep experimenting — and that future iterations of these tools could become more effective.
New Ransomware Variant Targets ESXi
In addition to the AI abuse, the study observed Aurora deploying a new Linux ransomware variant specifically designed to target ESXi environments, which are widely used in data centers and enterprise virtualization. The attackers used a custom NetExec LDAP module called esxi_finder.py to scan for VMware ESXi hypervisors and vCenter servers inside victim networks.
The variant encrypts virtual machine files while skipping system volumes, keeping the hypervisor itself bootable so that the victim can read the ransom demand. This is a strategic choice, as it maximizes disruption while ensuring the ransomware note is actually seen.
Second Cluster of Activity
Gambit researchers also reported a second cluster of activity, attributed with medium confidence to an Aurora operator, that targeted eight victim organizations across Israel, Germany, Austria, Spain, the US, and Argentina. This suggests the group is expanding its reach, though the medium confidence level indicates some uncertainty in the attribution.
Aurora ransomware activity has been observed since April 2026, with the group operating a data leak site and targeting organizations across multiple countries. The use of a data leak site is a common tactic to pressure victims into paying, and the group's willingness to adopt new tools like AI agents suggests an adaptive and evolving threat.
Stakes for Defenders
The integration of AI into ransomware operations could have significant implications for cybersecurity teams. If AI agents become more reliable at executing exploitation tasks, the cost and skill required to launch a ransomware attack could drop, potentially leading to more frequent or more sophisticated incidents. Organizations may need to monitor not just for known malware signatures, but for unusual AI-driven behavior on their networks.
While this is a single report from one research firm, it aligns with broader industry concerns about AI being used to supercharge cyber threats. The fact that attackers are already experimenting with tools like Cursor Agent suggests that AI-assisted intrusion is no longer a hypothetical — it is happening now, and defenders should prepare for a future where AI plays a larger role on both sides of the cybersecurity battle.
Sources
- Infosecurity Magazine Original source
Continue Reading
TeamPCP arrests expose supply chain risk
Alleged masterminds of TeamPCP, tied to Shai-Hulud worm, arrested in Perth with FBI help.
CRPx0's big claims and where they lead
CRPx0's victim count rose from under 10 to 48 organizations since June, but experts urge caution over unverified claims.
UK Airport Group Data Breach Hits Pre-Holiday Travelers
MAG says customer data was stolen from its systems, warning of phishing risks ahead of peak travel.