logo

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

ID: 6266279a-745d-5b0a-85f8-122c4f1691a4

STIX ID: report--6266279a-745d-5b0a-85f8-122c4f1691a4

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-08-31

Date Updated: 2026-08-31

Author: [email protected] (The Hacker News)

...
...

The report documents active Aurora (Aur0ra) ransomware activity and a separate Gryxa AI-assisted toolkit operation: Aurora operators used AI coding assistants (Cursor/Anthropic Claude Sonnet) to plan and execute cross-platform attacks—compiling Zig-based encryptors for Windows and Linux/ESXi, performing AD CS exploitation, lateral movement, privilege abuse, data exfiltration and Defender/log tampering—while exposed infrastructure revealed operator toolkits, shell history, victim lists and ransom-split details; Gryxa is an AI-built RMM-based implant that persists, steals Chromium credentials, records remediation, and can disable endpoint protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.