Aurora Ransomware Hackers Used AI to Attack Companies Across Nine Countries | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


A Russian-speaking ransomware operator used an artificial intelligence coding agent to assist with attacks on companies across nine countries, giving researchers a rare look at how AI is becoming part of real-world cybercrime.

The activity was uncovered after cybersecurity firms CloudSEK and Gambit Security found an exposed server containing the operator’s files, attack notes and conversations with an AI agent. The evidence covers activity between April and July 2026 and links the operator to more than 20 organisations.

What makes the case significant is not simply that hackers used AI. Investigators found the AI being used during actual intrusions, including reconnaissance, privilege checks and exploitation after attackers had already gained access to victim networks.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

First, what are Aurora, ransomware affiliates and AI agents?

Aurora is a ransomware operation in which criminals encrypt or steal a victim’s data and demand payment to restore access or prevent the stolen information from being published.

An “affiliate” is a criminal partner working with a larger ransomware operation. Instead of one group handling everything, the affiliate may break into a company, steal data and deploy the ransomware, then share the ransom with the operators.

An AI coding agent goes a step beyond a normal chatbot. It can work with software tools and carry out multi-step technical tasks after receiving instructions. In this case, investigators found the operator using Cursor’s AI agent, powered by Anthropic’s Claude model, during intrusions.

The important point is that the AI did not independently choose victims or launch the campaign. The human attacker supplied credentials or an existing route into the victim network and then used the agent to perform parts of the technical work.

Hackers used AI after getting inside

Gambit Security found 28 chat sessions between the operator and Cursor’s AI agent. The sessions showed the attacker asking the agent to perform tasks inside victim environments.

These included checking what permissions a compromised account had, scanning internal networks and configuring connections to victim systems. In some instances, the attacker simply gave the AI an objective and selected one of the next steps it suggested.

The operator also repeatedly described the activity as a legitimate security test. When the AI refused certain requests, investigators found that the attacker restarted conversations and repeated the claim that the work was authorised.

This exposed a weakness in relying on an AI system to judge intent from a user’s explanation. A malicious operator could present a real intrusion as a harmless simulation and attempt to persuade the agent to continue.

CloudSEK found that the operator used Cursor for planning as well as hands-on activity. One recovered attack plan involving Active Directory Certificate Services was written in Russian, supporting the assessment that the operator was Russian-speaking.

The attackers were not just testing AI

The recovered material showed a complete criminal workflow.

CloudSEK found Windows and Linux/ESXi versions of the Aurora ransomware. The Windows version could interfere with recovery mechanisms, while the Linux and ESXi version could stop virtual machines before encrypting data.

The victim list covered manufacturing, food and agriculture, professional services, transport, consumer goods and IT infrastructure. CloudSEK said the operator appeared to be opportunistic rather than focused on one particular industry.

The investigation also followed the money. CloudSEK and blockchain intelligence company TRM Labs traced cryptocurrency payments through several wallets and found links between multiple victim payments and a wider laundering infrastructure. One recovered negotiation showed an affiliate receiving a share of the ransom, with reported splits ranging from 54% to 79% depending on the case.

The exposed server therefore revealed something unusually complete: not just how the criminals entered companies, but how they planned attacks, deployed ransomware and handled the money afterwards.

AI is becoming another tool in the ransomware chain

The Aurora case is part of a broader change in cybercrime.

In 2025, security researchers identified PromptLock, a ransomware prototype that used a local AI model to generate malicious scripts. IBM later reported another likely AI-generated malware family, showing that criminals were moving from simply asking AI for advice towards incorporating AI into malware development and attack operations.

Aurora is different in one important way. The AI was not itself the ransomware. Instead, a human criminal used a commercial coding agent to reduce the amount of manual technical work required during an intrusion.

That distinction matters because it points to a more immediate problem. Attackers do not necessarily need an autonomous AI capable of running an entire cyberattack. Even a tool that makes individual stages faster can lower the time, skill and effort needed to compromise a company.

For businesses, that means traditional security controls remain critical. CloudSEK recommends tighter protection around Active Directory, privileged accounts and backup infrastructure, because compromising those systems can allow attackers to move deeper into a network and make recovery much harder.

The exposed server also delivered an uncomfortable lesson for the attackers themselves. Their own operational mistake gave researchers access to months of evidence that would otherwise have remained hidden.

What this means for you: For individuals, the immediate risk is not that an AI suddenly decides to hack your phone or bank account. The bigger concern is that criminals can use AI to make existing scams, credential theft and intrusion techniques faster and easier, so strong passwords, multi-factor authentication and timely software updates remain essential.

For companies, the warning is more urgent: assume that an attacker may now have AI-assisted tools available after gaining even limited access. The priority should be detecting unusual account activity early, restricting privileged access and keeping critical backups isolated from the main network.

——————————————————–


Click Here For The Original Source.

.........................