Ransomware Aurora ransomware actors leverage AI tool for exploitation campaigns August 28, 2026 Share By SC Staff Per Infosecurity Magazine, threat actors associated with Aurora ransomware have been observed exploiting SpaceXAI's Cursor Agent tool to facilitate their exploitation campaigns. A study by Gambit Security's Threat Intelligence team revealed that these actors used Claude Sonnet through Cursor Agent to aid in various malicious activities against at least 10 victims between April 8 and May 26, 2026. The Aurora ransomware group utilized Cursor Agent for post-compromise activities, providing it with credentials or existing access to victim networks. Tasks included environmental reconnaissance, such as scanning for hosts and identifying user privileges, and deploying exploitation tools like NetExec and Nmap. The actors also directed Cursor Agent to perform certificate attacks using Certipy and install VPN clients or proxychains. While the AI tool did not always succeed on the first attempt, requiring multiple refinements, its use demonstrates a trend of threat actors experimenting with AI to enhance campaign efficiency. The Gambit study also noted Aurora's deployment of a new Linux ransomware variant targeting VMware ESXi environments, capable of encrypting virtual machine files while keeping the hypervisor bootable to display ransom demands. Aurora ransomware activity has been ongoing since April 2026, with the group targeting organizations globally and operating a data leak site. Source: Infosecurity Magazine An In-Depth Guide to Ransomware Get essential knowledge and practical strategies to protect your organization from ransomware attacks. Learn More SC Staff Related Breach Why Ransomware Economics Favor Volume Over Prestige Attacks SC Editorial Intelligence , expert reviewed August 27, 2026 Breach Carhartt data breach claims inflated by synthetic data, analysis finds SC Staff August 26, 2026 ShinyHunters had claimed to leak 50GB of Carhartt's data on August 13, following a negotiation attempt after an initial extortion demand of $3.3 million. Breach LACMA data breach exposes customer and employee information SC Staff August 26, 2026 The Los Angeles County Museum of Art (LACMA), one of the largest art museums in the western United States, has announced that a data breach last year exposed sensitive customer and employee information. Related Events Cybercast Ransomware reloaded: Finding resilience when attackers wield AI On-Demand Event Virtual Conference Ransomware Resilience: Strategies to Defend, Mitigate, and Recover On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds