Aurora Ransomware Abuses Cursor AI and Claude Sonnet in ESXi Attacks
Aurora, also tracked as Aur0ra, is a Russian-speaking ransomware operation active since April 2026. Its core team appears to develop repeatable Active Directory intrusion playbooks while affiliates deploy encryptors and negotiate payments. The case matters because it shows commercial coding assistants moving beyond code generation into hands-on post-compromise work, helping attackers map networks, assess privileges and target VMware ESXi infrastructure. Aurora also built its encryptor in Zig, allowing the same codebase to produce Windows and Linux/ESXi payloads.
CloudSEK and TRM Labs said on Sept. 1 that Aurora had victimized more than 20 organizations across nine countries from April through July, gaining domain-level interactive access at 17 and listing four on its leak site. Blockchain analysis indicated two possible ransom payments. Gambit Security separately traced AI-assisted activity against 10 companies between April 8 and May 21. Operators used Russian-language prompts in Cursor and, in some intrusions, Claude Sonnet to scan networks, attempt NTLM relay attacks and locate ESXi and vCenter systems before encrypting virtual machines.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →