Aurora Ransomware Uses AI Coding Tools in Attacks
CloudSEK and Gambit Security find Aurora operators used Cursor AI to plan Russian-language attacks on 20-plus organizations in nine countries.

A Russian-speaking cybercrime group behind the Aurora ransomware operation has been using the Cursor AI coding assistant to plan and coordinate attacks, according to separate research published this week by CloudSEK and Gambit Security.
Gambit Security’s timeline covers 10 confirmed victims between April 8 and May 21, 2026. CloudSEK’s broader analysis accounts for 20-plus organizations across nine countries between April and July. Named victims include Belgian cleaning-chemical manufacturer Christeyns, German door systems company Teckentrup, the Helideck Certification Agency, US title company Bayou Title, an Argentine pharmaceutical distributor, and an Italian manufacturer.
How Cursor fit into the operation
Aurora’s operators ran Cursor in agentic mode, using it as a planning and coordination layer rather than a code-writing shortcut. According to the researchers, the actors composed attack plans in Russian inside the tool while explicitly configuring CIS (Commonwealth of Independent States) IP ranges as off-limits. That exclusion is a standard practice among Russian-speaking cybercrime groups and reflects the unwritten arrangement that operations avoid drawing domestic attention.
The AI-assisted planning fed into conventional post-exploitation tooling: Nmap and NetExec for reconnaissance, domain enumeration, privilege escalation, NTLM relay and certificate attacks, VPN client configuration, and proxychains routing. Cursor provided the operational interface; the attack techniques themselves were standard.
Researchers gained visibility into the toolkit through exposed attacker infrastructure, which revealed shell history, tooling, and a subset of encryption keys. The Aurora encryptor exists in both Windows (sap.exe) and Linux/ESXi (encrypt.out) variants, written in the Zig programming language.
What the pattern suggests
The CIS carve-out is worth sitting with. Configuring and testing a targeting exclusion list is logistical overhead, not a technical necessity. The fact that this step was managed inside an AI planning tool says something about where the friction is being felt in running a multi-country, Russian-language operation against English-language infrastructure: not in the attack techniques, which are conventional, but in the coordination and translation layer.
AI coding assistants with strong multilingual capability reduce that friction meaningfully. An agentic tool that understands both Russian operational planning and English-language network reconnaissance scripts is, from the attackers’ perspective, a fluent interpreter that also reads network diagrams.
Neither report indicates that the Cursor layer itself was a point of compromise or that it could be disabled as a defensive measure. Investigators found the evidence in exposed infrastructure, not in the AI tool’s outputs. The indicators of compromise are in the network behavior: the scanning signatures, the lateral movement, the encryptor binaries. That’s the same place defenders have always looked.
Analysis: AI coding assistants appearing in documented ransomware operations is not new as of this report, but Aurora’s campaign establishes something more specific: the tooling is now embedded in multi-month, multi-country operations targeting industrial and healthcare-adjacent organizations with named victims and verified timelines. That’s operational maturity, not experimentation. For the threat-intel community, the more significant finding may be that exposed infrastructure was what broke this open, not behavioral detection catching something novel. Aurora’s techniques were conventional enough that they might not have surfaced otherwise.
For context on AI tooling appearing on both sides of the threat landscape, see ESET’s H1 2026 report on malicious AI skills and quishing trends, OpenAI agents breaching Hugging Face via reward hacking, and the NemoClaw flaw that let webpages poison local AI agents.
Found this useful? Share it.


