Cybersecurity experts have uncovered a significant development in the activities of the Aurora ransomware group, known for its sophisticated cyber attacks. This group has been utilizing advanced artificial intelligence tools, specifically SpaceX’s AI-powered coding assistant Cursor, to infiltrate and exploit networks globally, according to findings from CloudSEK and Gambit Security.
AI Tools in Cybercrime
Investigations revealed that the Russian-speaking threat group behind Aurora ransomware has employed Cursor to plan and execute attacks. This AI tool facilitated the group’s ability to breach systems while strategically excluding targets within the Commonwealth of Independent States (CIS). CloudSEK’s research highlighted that the group’s exposed infrastructure revealed months of activity across multiple countries, with four victims already identified on its data leak platform.
First identified in May 2026, Aurora ransomware has primarily targeted Windows systems. It has been continuously evolving, incorporating new features to enhance its attack capabilities. As per Ransomware.Live data, 33 organizations across the U.S., Europe, and Canada have fallen victim to Aurora’s attacks.
Complex Attack Strategies
In a detailed case, Black Hills Information Security illustrated how the group gained initial access through aggressive email campaigns, followed by impersonating IT support to establish remote connections using the Xray-core utility. The attack sequence involved lateral movements across network protocols, aiming to acquire high-level administrative access. Once inside, the attackers disabled security measures before exfiltrating sensitive data and initiating encryption.
Aurora’s operators have developed ransomware binaries for both Windows and Linux platforms, written in the Zig programming language. The Windows version inhibits system recovery by deleting shadow copies, whereas the Linux variant targets virtual machines before encryption begins.
Economic Impact and Future Threats
Financial analysis of the ransomware’s operations revealed a structured affiliate model, where affiliates received a significant portion of the ransom, ranging from 54% to 79%, depending on the victim’s financial standing. The funds are then laundered and cashed out, highlighting the economic motivations behind these cyber threats.
Gambit Security’s recent insights further disclosed the use of Cursor Agent, which leverages Anthropic’s Claude Sonnet, to aid in exploiting 10 target organizations. The AI was tasked with various exploitation activities, such as installing VPNs, scanning networks, and executing certificate attacks, showing the evolving complexity of such cyber operations.
Emergence of New AI-Assisted Threats
Concurrently, a new toolkit named Gryxa has surfaced, showcasing the use of AI in orchestrating comprehensive cyber operations. Gryxa employs legitimate remote monitoring software for unauthorized access, maintaining persistence through multiple mechanisms. It also targets Chromium-based browser credentials and disrupts endpoint protection systems to facilitate data theft.
This development underscores the growing reliance on AI tools by cybercriminals to enhance their attack strategies, posing significant challenges for cybersecurity defenses. The ongoing evolution of such threats necessitates constant vigilance and adaptation by organizations worldwide.
