logo

Aurora Ransomware Affiliate Uses Cursor AI to Plan Attacks Against 20+ Organizations

ID: f891fc71-ca4b-5f6c-94ce-066866118a28

STIX ID: report--f891fc71-ca4b-5f6c-94ce-066866118a28

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: Varshini

...
...

CloudSEK uncovered an exposed open directory containing months of activity by a Russian-speaking Aurora ransomware affiliate that targeted 20+ organizations (17 with domain-level or interactive access). The leak included credential dumps, AD data, Kerberos tickets, exploit tools, Cursor AI chat logs used to plan attacks, and Aurora encryptors for Windows (sap.exe) and Linux/ESXi (encrypt.out) that include anti-recovery and VM-stopping capabilities; investigators also recovered a ransom negotiation key and linked Bitcoin laundering infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.