Aurora Ransomware Affiliate Exposed Using Cursor AI to Plan Enterprise Attacks
A Russian-speaking affiliate linked to the Aurora ransomware operation has been exposed after researchers discovered an unsecured open directory containing months of intrusion activity, stolen credentials, attack tools, and ransomware payloads.
CloudSEK reported that the operator targeted more than 20 organizations across nine countries between April and July 2026, successfully obtaining domain-level or interactive access at 17 victims.
The discovery provides an unusually detailed view of how a ransomware affiliate plans, executes, and manages attacks against enterprise environments.
The exposed Linux home directory was reportedly accessible through a file-listing service running on port 8888. Researchers found folders associated with victims, Kerberos tickets, credential dumps, Active Directory information, shell-history files, exploit utilities, Cursor AI chat logs, and Aurora ransomware binaries.
Aurora Ransomware Affiliate Exposed
Four organizations represented in the recovered material were subsequently named on Aurora’s public leak site. CloudSEK assessed with high confidence that the individual was operating as an Aurora affiliate conducting compromises directly rather than functioning as an initial-access broker that sells stolen access.
The affiliate reportedly relied on rented SOCKS proxy infrastructure to conceal connections to victim environments. Most of the observed proxy infrastructure consisted of virtual private servers hosted in Germany and the United States.
The operational setup allowed the attacker to conduct reconnaissance, credential attacks, lateral movement, and post-compromise activity while obscuring the original source of connections.
One of the most notable findings was the attacker’s use of Cursor, an AI-powered coding assistant, to plan portions of the intrusion in Russian.
Recovered conversations showed extended discussions about Active Directory Certificate Services exploitation and other techniques for compromising Windows domains.
The AI-assisted workflow appears to have been incorporated into a repeatable operational process rather than used merely for basic programming assistance.
Across multiple victims, the affiliate followed a consistent playbook. NetExec was used for LDAP and SMB discovery, password-policy analysis, ASREPRoasting, Kerberoasting, BloodHound data collection, and credential validation.
For privilege escalation and domain compromise, the toolkit contained custom scripts targeting the noPac attack chain and techniques associated with ADCS vulnerabilities including ESC1, ESC6, and ESC8. The operator also maintained NTLM-relay capabilities involving PetitPotam, PrinterBug, and DFSCoerce.
After gaining access, the attacker prepared stolen information using PowerShell-driven 7-Zip operations. The data was reportedly divided into chunks of approximately 50 GB for staging and transfer.
Investigators also documented browser credential theft, VPN credential validation, backup-system access, Active Directory compromise, and discovery of VMware ESXi infrastructure.
These activities demonstrate an emphasis on obtaining broad control over enterprise environments before ransomware deployment.
The exposed directory contained both Windows and Linux/ESXi versions of the Aurora encryptor. The binaries were reportedly written in Zig, an uncommon language in ransomware development, and appeared to share a common codebase.
The Windows payload, identified as sap.exe, included recovery-inhibition capabilities targeting volume shadow copies and System Restore, reducing the victim’s ability to recover systems without paying the attackers.
The Linux/ESXi payload, encrypt.out, was designed to identify and stop virtual machines before encrypting virtual-machine-related files.
Instead of placing a conventional ransom note on ESXi systems, the malware reportedly modified the SSH login banner to display the extortion message. This approach demonstrates how the operation adapts its ransomware deployment to virtualization infrastructure.
CloudSEK also recovered a key from the encryptor that enabled researchers to access a completed ransom negotiation. Working with TRM Labs, investigators traced the associated Bitcoin payment and identified connections to Aurora’s broader cryptocurrency laundering network.
The findings highlight how operational mistakes, such as exposing an attacker directory, can reveal infrastructure, tooling, victim information, ransomware samples, and financial activity across an entire criminal ecosystem.
Indicators of compromise identified in the investigation include the defanged Aurora negotiation portal ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid[.]onion and the Windows ransomware executable sap.exe.
Security teams should monitor for suspicious Kerberos and NTLM-relay activity, unauthorized ADCS operations, unusual PowerShell and 7-Zip processes, unexpected proxy connections, and modifications to ESXi SSH configurations.
No Comment! Be the first one.