Aurora Ransomware Operators Weaponise Cursor AI for Attacks
The Aurora ransomware group has been observed leveraging Cursor, an agentic AI coding assistant, to plan and execute ransomware attacks against more than 20 organisations across nine countries. Exposed infrastructure revealed the operators used Cursor to draft attack plans in Russian, including full Active Directory Certificate Services exploitation strategies, representing a concrete case of AI-assisted threat actor tradecraft. The encryptors target both Windows and Linux/ESXi environments and are written in Zig, with the group employing social engineering, lateral movement, and log-clearing to evade detection.