Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Actors Exploit AI Tool in Sophisticated Attacks

Modern office workspace with laptop, papers, and coding materials on tidy desk.

"The majority of the commands failed to achieve the stated objective on the first attempt, resulting in multiple refinements and changes to the commands and scripts used for each task," Gambit Security's researchers wrote — a single line that underlines a larger shift in the tools attackers are experimenting with.

Aurora's use of Claude Sonnet via SpaceX's Cursor Agent

Gambit Security’s Threat Intelligence team reported that Aurora ransomware operators ran the AI model Claude Sonnet through SpaceX’s Cursor Agent to assist in exploitation activities against 10 victims between April 8 and May 26, 2026. Cursor Agent — a developer-oriented tool that can complete complex coding tasks independently, run terminal commands and edit code — was provided with credentials or an existing route into victim environments and instructed to act on behalf of the operator.

Reconnaissance, enumeration and explicit objectives

The study records a range of reconnaissance tasks delegated to Cursor Agent. In some interactions attackers asked simple, outcome-oriented questions — for example, "tell me what rights the user has" — while in other exchanges they supplied detailed instructions about which tools to use and what steps to follow. The agent was instructed to enumerate domain privileges using NetExec’s BloodHound collector and to scan internal subnets with Nmap or NetExec.

Direct exploitation attempts: NTLM relay, certificate and tunneling techniques

Researchers observed Aurora using Cursor Agent for active exploitation as well as reconnaissance. The agent was tasked with attempting NTLM relay attacks by coercing authentication via PetitPotam, Coerce Plus, and PrinterBug. It was also instructed to run certificate attacks with Certipy. In other cases attackers told the agent to install a VPN client or proxychains, configure them, and connect to a victim using supplied credentials or an existing SOCKS tunnel.

Operational pattern: iterative failures, refinements and mixed success

Gambit’s reporting emphasizes that Cursor Agent did not consistently achieve its objectives on first attempt. According to the researchers, many commands failed initially and required multiple refinements and script changes. "Some eventually succeeded in achieving the objective, while others failed and returned only a report of the attempts to the attacker," the study says. That pattern — iterative trial, adjustment and occasional success — illustrates attackers treating AI agents as tools to accelerate experimentation, rather than as flawless substitutes for human operators.

ESXi-targeting Linux ransomware variant and broader Aurora activity

The Gambit study, published on August 27, also documents Aurora deploying a new Linux ransomware variant designed to target VMware ESXi environments. Operators used a custom NetExec LDAP module, esxi_finder.py, to search victim networks for ESXi hypervisors and vCenter servers. The ransomware encrypts virtual machine files but intentionally skips system volumes so the hypervisor can remain bootable and display the ransom demand.

Gambit researchers additionally observed a second cluster of activity they attribute with medium confidence to an Aurora operator: eight victim organizations targeted across Israel, Germany, Austria, Spain, the US and Argentina. Overall, Gambit notes Aurora activity dating back to April 2026 and operating a data leak site while targeting organizations in multiple countries.

What this means for technologists, procurement leaders and affected enterprises

  • Technologists and security teams: Expect adversaries to incorporate AI-assisted workflows into post-compromise playbooks. The Gambit study shows attackers delegating enumeration, exploitation orchestration and tunneling configuration to Cursor Agent, accepting iterative failures while refining prompts and scripts.
  • Procurement leaders: Tools designed for developer productivity — in this case Cursor Agent — can be repurposed by attackers when they have valid access. The research suggests vendors and buyers should consider how tooling that can run terminal commands and edit code might be constrained or monitored when credentials are exposed.
  • Affected enterprises: The observed ESXi-focused variant encrypts VM files but leaves hypervisors bootable to display demands. Organizations running virtualization infrastructure and LDAP-accessible services should be aware that custom discovery modules such as esxi_finder.py were used to locate targets inside networks.

The Gambit Security findings present a clear, narrow truth: attackers are experimenting with AI agents as another instrument in their toolkits, combining off‑the‑shelf and custom modules — from Cursor Agent-driven prompts to NetExec collectors and bespoke scripts like esxi_finder.py — to find and exploit gaps. Whether that experimentation produces a consistent new capability or simply accelerates trial-and-error depends on the same variables that have always mattered: access, credential hygiene, and the ability to detect and disrupt post-compromise activity.

Read the original Gambit Security report at: https://www.infosecurity-magazine.com/news/abuse-cursor-agent-ransomware/