Ransomware Hacker Uses AI to Plan Cyberattacks Against 20+ Orgs
Key Takeaways A Russian-speaking Aurora ransomware affiliate utilized an AI coding assistant, Cursor, to plan and execute attacks against over 20 organizations across nine countries. The...
Key Takeaways
- A Russian-speaking Aurora ransomware affiliate utilized an AI coding assistant, Cursor, to plan and execute attacks against over 20 organizations across nine countries.
- The attacker’s operations, spanning April to July 2026, were exposed through an unsecured server, providing unprecedented insight into their methods from initial intrusion to cryptocurrency payment.
- Victims included sectors such as manufacturing, food, agriculture, and professional services, with at least four organizations appearing on Aurora’s public leak site.
- The affiliate leveraged common Windows network abuse techniques, enhanced by AI for faster attack planning, and deployed custom Zig-based Aurora lockers for Windows, Linux, and ESXi environments.
A Russian-speaking affiliate of the Aurora ransomware group has been observed employing an AI coding assistant to strategize cyberattacks against more than 20 organizations. This marks a significant evolution in ransomware operations, where artificial intelligence is increasingly integrated into attack planning.
Table Of Content
Investigators gained a rare, comprehensive view into the operator’s activities, from initial network penetration to the final payment stages, due to an inadvertently exposed server. This detailed timeline of illicit operations ran from April to July 2026 and impacted entities in nine different countries.
The affiliate successfully achieved domain-level or interactive access within 17 targeted environments. Furthermore, four victims subsequently appeared on Aurora’s public data leak site. The affected industries spanned manufacturing, food production, agriculture, and professional services.
Unveiling the Attack Infrastructure
CloudSEK said in a report that the compromised directory provided a trove of information, including the affiliate’s toolkit, command history, stolen credentials, Cursor chat logs, and the Aurora encryptor. This evidence strongly indicates that the affiliate was directly involved in executing intrusions rather than merely acting as a broker selling access.
The findings illustrate a concerning trend where ransomware groups combine established Windows network exploitation methods with AI-powered assistance for accelerated planning. The operator utilized rented SOCKS proxies to establish access to victim networks, subsequently deploying a suite of tools for network discovery, password attacks, credential harvesting, data exfiltration, and the ultimate delivery of the encryption payload.
Ransomware Hacker Uses AI
During the latter stages of its documented activity, the affiliate extensively used Cursor, an AI coding assistant, to draft and refine attack sequences, all conducted in Russian. One particularly detailed session focused on developing an exploit against Active Directory Certificate Services (AD CS) within a victim’s environment. The chat logs reveal a dynamic, back-and-forth planning process with the AI, rather than simply generating predefined commands.
This integration of AI is crucial because it allows an attacker to rapidly translate reconnaissance findings into actionable next steps, significantly accelerating the operational tempo. While the underlying tactics, such as those seen in AI-assisted ransomware operations, may be familiar to defenders, the speed and efficiency gained through AI support present a heightened challenge.
The affiliate followed a consistent attack methodology. They employed NetExec to scan network services, extracted password policy details, and attempted ASREPRoasting and Kerberoasting to obtain password hashes for offline cracking. Additional data collection included SAM and LSA information, Group Policy exports, and BloodHound data for network mapping.
To deepen their access, the operator leveraged a custom noPac exploit, abused certificate services, and executed NTLM relay attacks using tools like PetitPotam, PrinterBug, and DFSCoerce. Organizations are urged to meticulously review warnings related to Active Directory credential theft, as compromise of the domain can expose virtually all accounts, systems, and recovery options across the entire network.
The researchers noted that the target lists and logs did not contain IP ranges or domains associated with CIS (Commonwealth of Independent States) countries. While this pattern alone does not definitively identify the attacker’s origin, the operator’s personal notes, custom tool documentation, and the AI planning sessions were all in Russian, further solidifying CloudSEK’s assessment of the affiliate’s linguistic background.
Encryption and Defence Steps
Aurora’s ransomware binaries for Windows and Linux/ESXi environments were uniquely developed from a single Zig codebase, an unusual choice for ransomware. The Windows variant was named sap.exe, while the Linux and ESXi build was called encrypt.out. Both were retrieved from a public Cloudflare R2 bucket and transferred to staging hosts via SCP.
On Windows systems, the malware first attempts to delete volume shadow copies, resize shadow storage, and disable System Restore before proceeding with file encryption. The ESXi variant terminates running virtual machines and encrypts virtual machine files, making ESXi ransomware attack risks particularly severe due to their potential to disrupt multiple critical business systems. Recovered negotiation data confirms that at least one victim paid the ransom demand.
CloudSEK, in collaboration with TRM Labs, traced the payments, confirming two victim payments and identifying two additional payments consistent with separate victims. These funds were laundered through shared infrastructure before being cashed out.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| Onion address | ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid[.]onion | Aurora Tor negotiation site |
| SHA-256 | eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207 | sap.exe Windows locker |
| SHA-256 | a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe | encrypt.out Linux and ESXi locker |
| Filename | !!!README!!!DO_NOT_DELETE.txt | Aurora ransom note |
| IPv4 | 172.86.113.245 | Operator VPS |
| IPv4 | 172.86.90.75 | Operator VPS |
| IPv4 | 144.172.116.150 | Operator VPS |
| IPv4 | 104.194.134.167 | Operator VPS used as SOCKS relay |
| IPv4 | 89.106.83.49 | Rented SOCKS pivot |
| IPv4 | 23.234.108.48 | Rented SOCKS pivot |
| IPv4:Port | 167.88.167.37:50167 | C2 egress check |
| IPv4:Port | 45.61.148.166:21056 | Rented SOCKS pivot |
What You Should Do
- Disable LLMNR and NBT-NS protocols to prevent credential relay attacks.
- Implement SMB signing and Extended Protection for Authentication (EPA) to enhance security for SMB traffic.
- Restrict WinRM access to only approved administrative hosts and remove SMBv1 where it is still present.
- Conduct a thorough review of certificate templates for any risky configurations and ensure robust logging of all certificate requests and issuances to detect abuse quickly.
- Following a suspected domain compromise, rotate the
krbtgtpassword twice, ensuring full replication between each reset. - Protect browser-stored credentials, which are often targeted by attackers.
- Utilize separate credentials and network segments for backup systems to prevent ransomware from encrypting backups.
- Isolate or retire older, vulnerable systems that cannot be adequately secured.
- Harden virtualisation management interfaces, as highlighted in ransomware platform targeting ESXi environments, to limit the impact of an encryption event.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.