Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
ID: 6266279a-745d-5b0a-85f8-122c4f1691a4
STIX ID: report--6266279a-745d-5b0a-85f8-122c4f1691a4
Feed Name: The Hacker News
The report documents active Aurora (Aur0ra) ransomware activity and a separate Gryxa AI-assisted toolkit operation: Aurora operators used AI coding assistants (Cursor/Anthropic Claude Sonnet) to plan and execute cross-platform attacks—compiling Zig-based encryptors for Windows and Linux/ESXi, performing AD CS exploitation, lateral movement, privilege abuse, data exfiltration and Defender/log tampering—while exposed infrastructure revealed operator toolkits, shell history, victim lists and ransom-split details; Gryxa is an AI-built RMM-based implant that persists, steals Chromium credentials, records remediation, and can disable endpoint protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
