Mark RadarMARK RADAR
About
EN
Sign in

Aurora Ransomware Abuses Cursor AI and Claude Sonnet in ESXi Attacks

2 reports · First detected 2026-09-01 · Last active 2026-09-01

Aurora, also tracked as Aur0ra, is a Russian-speaking ransomware operation active since April 2026. Its core team appears to develop repeatable Active Directory intrusion playbooks while affiliates deploy encryptors and negotiate payments. The case matters because it shows commercial coding assistants moving beyond code generation into hands-on post-compromise work, helping attackers map networks, assess privileges and target VMware ESXi infrastructure. Aurora also built its encryptor in Zig, allowing the same codebase to produce Windows and Linux/ESXi payloads.

CloudSEK and TRM Labs said on Sept. 1 that Aurora had victimized more than 20 organizations across nine countries from April through July, gaining domain-level interactive access at 17 and listing four on its leak site. Blockchain analysis indicated two possible ransom payments. Gambit Security separately traced AI-assisted activity against 10 companies between April 8 and May 21. Operators used Russian-language prompts in Cursor and, in some intrusions, Claude Sonnet to scan networks, attempt NTLM relay attacks and locate ESXi and vCenter systems before encrypting virtual machines.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)