Aurora Ransomware Affiliate Uses Cursor AI to Plan Attacks Against 20+ Organizations
ID: f891fc71-ca4b-5f6c-94ce-066866118a28
STIX ID: report--f891fc71-ca4b-5f6c-94ce-066866118a28
Feed Name: Cyber Press
CloudSEK uncovered an exposed open directory containing months of activity by a Russian-speaking Aurora ransomware affiliate that targeted 20+ organizations (17 with domain-level or interactive access). The leak included credential dumps, AD data, Kerberos tickets, exploit tools, Cursor AI chat logs used to plan attacks, and Aurora encryptors for Windows (sap.exe) and Linux/ESXi (encrypt.out) that include anti-recovery and VM-stopping capabilities; investigators also recovered a ransom negotiation key and linked Bitcoin laundering infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
