Russian-speaking Aurora ransomware operators weaponized Cursor AI, a coding assistant powered by Anthropic’s Claude Sonnet model, to conduct hands-on exploitation against 10 targets between April and May 2026, according to independent findings disclosed by CloudSEK and Gambit Security on August 31. The campaign marks the first documented case of ransomware operators using an AI coding assistant for active keyboard exploitation, demonstrating how agentic AI tools can enable less-skilled threat actors to execute sophisticated network intrusions against more than 20 organizations across nine countries.
Aurora’s April Through July Campaign Affecting 20+ Organizations Across Nine Countries
The broader Aurora ransomware campaign spanned April through July 2026, affecting more than 20 organizations across nine countries. Within that window, Cursor Agent exploitation was documented between April 8 and May 21, 2026, against 10 specific targets. CloudSEK discovered the exposed infrastructure containing months of Aurora activity, while Gambit Security independently observed the Cursor Agent use against the 10 documented targets. The exposure of the Aurora operators’ infrastructure provided researchers with detailed logs of how the threat actors planned and executed their attacks using the AI coding assistant.
CloudSEK’s Discovery of Exposed Infrastructure Containing Months of Operator Activity
CloudSEK’s discovery of the exposed infrastructure revealed that the threat actors used Cursor to plan attacks in Russian and execute exploitation tasks including network scanning, domain privilege enumeration, and NTLM relay attack attempts. The logs captured the operators’ iterative use of the AI assistant: they would issue a command in Russian, receive guidance from Cursor on how to execute the task, attempt the exploitation, and then refine their approach based on failure feedback. This workflow shows the AI assistant functioning as a real-time advisor for attackers who lacked the technical depth to independently craft exploitation commands.
Aurora Operators’ Trial-and-Error Pattern Reveals Reliance on AI Iterative Guidance
Analysis of the exposed infrastructure logs revealed a pattern of trial and error: “the majority of the commands failed to achieve the stated objective on the first attempt, resulting in multiple refinements” before some eventually succeeded. This execution pattern suggests the operators relied on the AI assistant to iteratively adjust their approach when initial exploitation attempts failed, rather than possessing deep technical expertise themselves. The iterative refinement process—where the AI assistant provides alternative approaches after each failed attempt—allowed the Aurora operators to eventually succeed in network scanning, privilege enumeration, and NTLM relay attacks despite lacking the skills to execute these techniques manually.
Cursor AI Provided Executable Guidance for Privilege Escalation and Lateral Movement
The Aurora operators’ ability to repurpose Cursor AI for network intrusion tasks—issuing commands in Russian and receiving executable guidance for privilege escalation and lateral movement—shows how agentic AI systems can be weaponized without modification to the underlying tool. Cursor AI, which uses SpaceX technology to run Anthropic’s Claude Sonnet model, was designed as a legitimate coding productivity tool. The operators did not exploit a vulnerability in Cursor or modify the software; they simply used its intended functionality to guide them through multi-step attack chains.
First Documented AI-Assisted Ransomware Intrusion Establishes New Threat Modeling Precedent
No disclosure or vendor response accompanied the August 31 findings from CloudSEK and Gambit Security. The analysis highlights the dual-use risk of agentic AI tools: the same iterative problem-solving capabilities that assist developers in writing code can guide threat actors through multi-step intrusion chains, even when those actors lack the expertise to execute the attacks manually. The Aurora campaign establishes a precedent that defenders must account for in threat modeling—ransomware operators will test AI coding assistants as force multipliers for hands-on keyboard work, and the accessibility of these tools means lower-skill adversaries can now attempt techniques previously reserved for advanced persistent threat groups.
The documented use of Cursor AI for network scanning, privilege enumeration, and NTLM relay attacks demonstrates that AI coding assistants lower the technical barrier for ransomware intrusion work. Organizations should anticipate that threat actors will continue experimenting with commercially available AI tools to guide exploitation tasks, and that the trial-and-error workflow documented in the Aurora campaign—where repeated failures eventually lead to success through AI-assisted refinement—will become a common pattern as less-skilled operators gain access to iterative AI guidance systems.