Aurora ransomware actors leveraging AI coding tools
🛡️ Threat actors tied to the Aurora (Aur0ra) ransomware have been observed using AI coding assistants like Cursor to plan and execute intrusions, according to CloudSEK and Gambit Security. Exposed infrastructure revealed months of activity targeting organizations across multiple countries between April and July 2026, with both Windows and Linux encryptors written in Zig. The attack chain includes credential theft, lateral movement, AD CS exploitation, and disabling recovery mechanisms before encryption. Investigators also identified affiliate payout splits and evidence of agentic use of Anthropic's Claude Sonnet for hands-on exploitation tasks.
