logo

Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks

ID: 907b67db-5e1d-503b-a41c-5ac1bdb9c4ae

STIX ID: report--907b67db-5e1d-503b-a41c-5ac1bdb9c4ae

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-08-31

Date Updated: 2026-09-01

Author: Mayura Kathir

...
...

Aurora ransomware operators used an AI agent (Cursor Agent powered by Claude Sonnet) to assist iterative post-compromise activity across multiple victims while deploying a Linux ESXi-targeting encryptor (encrypt.out, SHA-256 a4af136d...) that enumerates and forcibly kills VMs before encrypting VMDK/VMX and related files; the report details tooling, attack workflow, AD-focused lateral techniques (Nmap, BloodHound, PetitPotam, Certipy), victim leak activity, and multiple IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.