Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical cPanel Vulnerability (CVE-2023-XXXX) Allows Full Server Control
August 28, 2026
Critical PaperCut NG/MF Vulnerability Actively Exploited in Attacks
August 28, 2026
GitLab Patches Critical AI Agent Flaw Allowing Code Execution
August 27, 2026
Home/CyberSecurity News/Ransomware Hacker Uses AI to Plan Cyberattacks Against 20+ Orgs
CyberSecurity News

Ransomware Hacker Uses AI to Plan Cyberattacks Against 20+ Orgs

Key Takeaways A Russian-speaking Aurora ransomware affiliate utilized an AI coding assistant, Cursor, to plan and execute attacks against over 20 organizations across nine countries. The...

Emy Elsamnoudy
Emy Elsamnoudy
August 27, 2026 4 Min Read
7 0

Key Takeaways

  • A Russian-speaking Aurora ransomware affiliate utilized an AI coding assistant, Cursor, to plan and execute attacks against over 20 organizations across nine countries.
  • The attacker’s operations, spanning April to July 2026, were exposed through an unsecured server, providing unprecedented insight into their methods from initial intrusion to cryptocurrency payment.
  • Victims included sectors such as manufacturing, food, agriculture, and professional services, with at least four organizations appearing on Aurora’s public leak site.
  • The affiliate leveraged common Windows network abuse techniques, enhanced by AI for faster attack planning, and deployed custom Zig-based Aurora lockers for Windows, Linux, and ESXi environments.

A Russian-speaking affiliate of the Aurora ransomware group has been observed employing an AI coding assistant to strategize cyberattacks against more than 20 organizations. This marks a significant evolution in ransomware operations, where artificial intelligence is increasingly integrated into attack planning.

Table Of Content

  • Key Takeaways
  • Unveiling the Attack Infrastructure
  • Ransomware Hacker Uses AI
  • Encryption and Defence Steps
  • Indicators of Compromise (IoCs)
  • What You Should Do

Investigators gained a rare, comprehensive view into the operator’s activities, from initial network penetration to the final payment stages, due to an inadvertently exposed server. This detailed timeline of illicit operations ran from April to July 2026 and impacted entities in nine different countries.

The affiliate successfully achieved domain-level or interactive access within 17 targeted environments. Furthermore, four victims subsequently appeared on Aurora’s public data leak site. The affected industries spanned manufacturing, food production, agriculture, and professional services.

Unveiling the Attack Infrastructure

CloudSEK said in a report that the compromised directory provided a trove of information, including the affiliate’s toolkit, command history, stolen credentials, Cursor chat logs, and the Aurora encryptor. This evidence strongly indicates that the affiliate was directly involved in executing intrusions rather than merely acting as a broker selling access.

The findings illustrate a concerning trend where ransomware groups combine established Windows network exploitation methods with AI-powered assistance for accelerated planning. The operator utilized rented SOCKS proxies to establish access to victim networks, subsequently deploying a suite of tools for network discovery, password attacks, credential harvesting, data exfiltration, and the ultimate delivery of the encryption payload.

Ransomware Hacker Uses AI

During the latter stages of its documented activity, the affiliate extensively used Cursor, an AI coding assistant, to draft and refine attack sequences, all conducted in Russian. One particularly detailed session focused on developing an exploit against Active Directory Certificate Services (AD CS) within a victim’s environment. The chat logs reveal a dynamic, back-and-forth planning process with the AI, rather than simply generating predefined commands.

This integration of AI is crucial because it allows an attacker to rapidly translate reconnaissance findings into actionable next steps, significantly accelerating the operational tempo. While the underlying tactics, such as those seen in AI-assisted ransomware operations, may be familiar to defenders, the speed and efficiency gained through AI support present a heightened challenge.

The affiliate followed a consistent attack methodology. They employed NetExec to scan network services, extracted password policy details, and attempted ASREPRoasting and Kerberoasting to obtain password hashes for offline cracking. Additional data collection included SAM and LSA information, Group Policy exports, and BloodHound data for network mapping.

To deepen their access, the operator leveraged a custom noPac exploit, abused certificate services, and executed NTLM relay attacks using tools like PetitPotam, PrinterBug, and DFSCoerce. Organizations are urged to meticulously review warnings related to Active Directory credential theft, as compromise of the domain can expose virtually all accounts, systems, and recovery options across the entire network.

The researchers noted that the target lists and logs did not contain IP ranges or domains associated with CIS (Commonwealth of Independent States) countries. While this pattern alone does not definitively identify the attacker’s origin, the operator’s personal notes, custom tool documentation, and the AI planning sessions were all in Russian, further solidifying CloudSEK’s assessment of the affiliate’s linguistic background.

Encryption and Defence Steps

Aurora’s ransomware binaries for Windows and Linux/ESXi environments were uniquely developed from a single Zig codebase, an unusual choice for ransomware. The Windows variant was named sap.exe, while the Linux and ESXi build was called encrypt.out. Both were retrieved from a public Cloudflare R2 bucket and transferred to staging hosts via SCP.

On Windows systems, the malware first attempts to delete volume shadow copies, resize shadow storage, and disable System Restore before proceeding with file encryption. The ESXi variant terminates running virtual machines and encrypts virtual machine files, making ESXi ransomware attack risks particularly severe due to their potential to disrupt multiple critical business systems. Recovered negotiation data confirms that at least one victim paid the ransom demand.

CloudSEK, in collaboration with TRM Labs, traced the payments, confirming two victim payments and identifying two additional payments consistent with separate victims. These funds were laundered through shared infrastructure before being cashed out.

Indicators of Compromise (IoCs)

Type Indicator Description
Onion address ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid[.]onion Aurora Tor negotiation site
SHA-256 eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207 sap.exe Windows locker
SHA-256 a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe encrypt.out Linux and ESXi locker
Filename !!!README!!!DO_NOT_DELETE.txt Aurora ransom note
IPv4 172.86.113.245 Operator VPS
IPv4 172.86.90.75 Operator VPS
IPv4 144.172.116.150 Operator VPS
IPv4 104.194.134.167 Operator VPS used as SOCKS relay
IPv4 89.106.83.49 Rented SOCKS pivot
IPv4 23.234.108.48 Rented SOCKS pivot
IPv4:Port 167.88.167.37:50167 C2 egress check
IPv4:Port 45.61.148.166:21056 Rented SOCKS pivot

What You Should Do

  • Disable LLMNR and NBT-NS protocols to prevent credential relay attacks.
  • Implement SMB signing and Extended Protection for Authentication (EPA) to enhance security for SMB traffic.
  • Restrict WinRM access to only approved administrative hosts and remove SMBv1 where it is still present.
  • Conduct a thorough review of certificate templates for any risky configurations and ensure robust logging of all certificate requests and issuances to detect abuse quickly.
  • Following a suspected domain compromise, rotate the krbtgt password twice, ensuring full replication between each reset.
  • Protect browser-stored credentials, which are often targeted by attackers.
  • Utilize separate credentials and network segments for backup systems to prevent ransomware from encrypting backups.
  • Isolate or retire older, vulnerable systems that cannot be adequately secured.
  • Harden virtualisation management interfaces, as highlighted in ransomware platform targeting ESXi environments, to limit the impact of an encryption event.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwareransomwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Veeam Backup & Replication Flaw Exposes Guest OS Credentials

Next Post

Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine Cryptocurrency

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TP-Link Kasa Smart Home Vulnerability Lets Attackers Disrupt Devices
August 27, 2026
CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks
August 27, 2026
Two Australians Charged for TeamPCP Supply Chain Attacks
August 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us