"The operator used Cursor, an agentic coding assistant, to plan attacks in Russian, while excluding CIS ranges and CIS-country domains, without exception," CloudSEK warned.
How Aurora enlisted Cursor and Claude Sonnet
Two independent examinations — by CloudSEK and Gambit Security — show the Aurora (aka Aur0ra) ransomware group gave commercial AI coding agents a hands-on role in breaching networks. CloudSEK said exposed infrastructure revealed "months of activity" that targeted more than 20 organizations across nine countries between April and July 2026, while Gambit Security reported the operator using Cursor Agent running Anthropic's Claude Sonnet to assist exploitation against 10 targets between April 8 and May 21, 2026.
Gambit quoted its director of threat intelligence, Eyal Sela: "In these cases the agent was given credentials or an existing route into the victim organization. Then it was tasked with various exploitation activities." In practice, the human operator handed the agent objectives or tools to run, and in several cases merely selected a numbered option from the agent's suggested next steps.
Tasks delegated to the agent: specific techniques and tools
- Installing VPN clients or proxychains and configuring connections to victims using supplied credentials or an existing SOCKS tunnel.
- Scanning internal subnets with Nmap or NetExec and enumerating domains with NetExec's BloodHound collector to report on a supplied user's privileges.
- Attempting NTLM relay attacks by coercing authentication with PetitPotam, Coerce Plus, and PrinterBug, and relaying credentials with Impacket ntlmrelayx.
- Running certificate attacks with Certipy.
- Using a Python script ("esxi_finder.py") to locate VMware ESXi hypervisors and vCenter servers for the Linux variant.
Gambit added that "the majority of the commands failed to achieve the stated objective on the first attempt," requiring multiple refinements; some sequences eventually succeeded, others returned only reports of failed attempts.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadAurora's encryptor and operational tradecraft, per CloudSEK and others
CloudSEK recovered both Windows and Linux/ESXi encryptors and traced them to a single Zig codebase compiled separately for each platform. The Windows binary (sap.exe) and the Linux/ESXi build (encrypt.out) are static builds from that shared source; CloudSEK noted the Windows binary still contains usage examples from the Linux build, a leftover of a common source tree.
The Windows variant actively inhibits recovery by deleting volume shadow copies and disabling System Restore via the Registry. The Linux/ESXi variant attempts to forcefully stop every virtual machine on a host before beginning encryption. Black Hills Information Security also documented an attack pattern where initial access came from aggressive email bombing, followed by social engineering phone calls posing as IT help desk personnel and establishing remote access via the open-source Xray-core utility.
The broader attack chain includes lateral movement via SMB, LDAP, WinRM, RDP, and RPC; seizing high-privilege administrator accounts; clearing logs and disabling Microsoft Defender to evade detection; harvesting and exfiltrating data; and finally deploying the encryptor.
Finances, affiliate model, and visible artifacts
CloudSEK and other recoveries revealed a ransom negotiation that could be accessed via a key recovered from the encryptor, and identified a cluster of four cryptocurrency wallets. Wallet analysis shows affiliates receiving between 54% and 79% of ransom proceeds, with the remaining share going to administrators. CloudSEK said the affiliate cut is decided per victim and "depends on the ransom amount demanded and the victim's revenue figures." The illicit funds are then laundered and cashed out, the reports say.
Ransomware.Live lists 33 victims across the U.S., Germany, the Netherlands, Canada, and the U.K. Reuters, cited by the reporting, named several affected companies it identified: Christeyns, Teckentrup, Helideck Certification Agency, Bayou Title, an Argentine pharmaceutical distributor, and an Italian manufacturer.
Gryxa toolkit: a separate AI-built operation and persistence model
ReliaQuest disclosed a separate AI-assisted toolkit, Gryxa, used in an initial-access campaign that targeted 324 hosts. Gryxa turns legitimate remote monitoring and management (RMM) software into covert access, maintains persistence through multiple restart mechanisms and scheduled tasks, and steals credentials saved in Chromium-based browsers by bypassing app-bound encryption protections. Harvested credentials are transmitted to the actor via Telegram.
Gryxa also records remediation activity and uploads logs and artifacts after visible RMM implants are removed. If the actor's relay becomes unreachable, the toolkit attempts to disable or uninstall endpoint protection agents such as Microsoft Defender within roughly 10–13 minutes, and re-enables Defender once the relay is accessible. ReliaQuest said the actor likely jailbroke an AI coding agent by presenting the development as an "authorized internal deployment" and that Gryxa is likely delivered via phishing.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: Expect AI agents to be used as hands-on operators for routine exploitation steps; defensive controls need to account for automated refinement loops and agent-assisted pivoting across internal networks.
- Policymakers and regulators: The use of commercial AI tooling to directly assist intrusions — even as model providers add guardrails — raises questions about vendor mitigation, disclosure expectations, and financial-transaction tracing tied to wallet clusters and affiliate splits.
- Affected enterprises and procurement leaders: Shared source trees and cross-platform builds can leave telling artifacts; exposure of internal directories and compile artifacts can reveal months of activity and negotiation keys, creating forensic opportunities and new hygiene priorities.
The forensic record in these exposures is stark: actor chat logs, a recovered encryption key, compiled binaries, and wallet clusters together trace not just what was done, but how it was automated and funded. As CloudSEK, Gambit Security, and ReliaQuest show in different parts of this story, commercially available AI agents and AI-built toolkits are being grafted onto familiar intrusion playbooks — and, in several documented cases, they carried the operation from foothold to encryption. Whether model providers' guardrails, network defenses, and financial tracing will keep pace with this operational blending is the practical question these findings leave squarely on the table.




