• bitcoinBitcoin(BTC)$79,967.002.31%
  • ethereumEthereum(ETH)$2,511.492.54%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$709.501.62%
  • rippleXRP(XRP)$1.465.67%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$106.4611.03%
  • tronTRON(TRX)$0.3378850.99%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-0.67%
  • HyperliquidHyperliquid(HYPE)$83.852.71%
  • dogecoinDogecoin(DOGE)$0.0886994.22%
  • zcashZcash(ZEC)$796.733.72%
  • RainRain(RAIN)$0.0174670.05%
  • USDSUSDS(USDS)$1.00-0.01%
  • chainlinkChainlink(LINK)$11.844.82%
  • whitebitWhiteBIT Coin(WBT)$73.782.15%
  • leo-tokenLEO Token(LEO)$9.340.64%
  • moneroMonero(XMR)$456.694.60%
  • cardanoCardano(ADA)$0.2149844.19%
  • stellarStellar(XLM)$0.1875953.88%
  • bitcoin-cashBitcoin Cash(BCH)$269.702.58%
  • CantonCanton(CC)$0.1172471.44%
  • daiDai(DAI)$1.000.01%
  • USD1USD1(USD1)$1.000.00%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.411.21%
  • litecoinLitecoin(LTC)$50.140.21%
  • hedera-hashgraphHedera(HBAR)$0.0793042.96%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • avalanche-2Avalanche(AVAX)$7.513.27%
  • shiba-inuShiba Inu(SHIB)$0.0000053.94%
  • suiSui(SUI)$0.784.66%
  • crypto-com-chainCronos(CRO)$0.0607825.10%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • uniswapUniswap(UNI)$4.547.41%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • tether-goldTether Gold(XAUT)$4,575.08-0.63%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.02%
  • MemeCoreMemeCore(M)$1.12-1.25%
  • nearNEAR Protocol(NEAR)$1.934.93%
  • BittensorBittensor(TAO)$258.9312.95%
  • okbOKB(OKB)$113.492.49%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.140.05%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
  • pax-goldPAX Gold(PAXG)$4,579.35-0.70%
  • aaveAave(AAVE)$128.054.08%
  • Pump.funPump.fun(PUMP)$0.0049495.01%
  • AsterAster(ASTER)$0.723.61%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.0587670.73%
  • OndoOndo(ONDO)$0.3762634.31%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Ransomware Operator Ran Cursor Agent Inside Ten Victim Networks – Unite.AI

August 27, 2026
in AI & Technology
Reading Time: 4 mins read
A A
Ransomware Operator Ran Cursor Agent Inside Ten Victim Networks – Unite.AI
ShareShareShareShareShare

Gambit Security’s threat intelligence team has published a detailed account of the Aurora ransomware operation, including six weeks of session logs showing an operator driving SpaceX’s Cursor AI coding agent through hands-on exploitation inside ten target organizations between April 8, 2026 and May 21, 2026. Reuters, which first reported the findings on August 27, 2026, put the number of confirmed breached companies at at least seven.

YOU MAY ALSO LIKE

Visa ships a security AI that patches production code before any human reviews it

Live Updates From The Launch Of The Next S26

The investigation, authored by Gambit’s director of threat intelligence Eyal Sela and published August 27, 2026, rests on exposed infrastructure associated with the group, which has operated a data leak site and been reported active since roughly April 2026. The recovered material shows the operator running Cursor Agent with the model identifier claude-4.5-sonnet-thinking against live enterprise networks, and it reads less like an attack script than like a junior intruder working a shift with a senior engineer on call.

What the Cursor Sessions Show

In the victim networks where the agent was used, the operator handed Cursor Agent credentials or an existing route in, then tasked it with exploitation work: installing and configuring VPN clients or proxychains to connect through supplied credentials or an existing SOCKS tunnel; scanning internal subnets with Nmap or NetExec; enumerating domain privileges with NetExec’s BloodHound collector; coercing authentication for NTLM relay attacks with PetitPotam, Coerce Plus, and PrinterBug, relayed through Impacket’s ntlmrelayx; and running certificate attacks with Certipy.

The interaction pattern is the part worth sitting with. Sometimes the operator gave only an objective, such as reporting what rights a supplied user held. Sometimes the agent proposed next steps and the attacker simply replied with the number of one. Most commands failed on the first attempt, and the agent iterated through refinements until some tasks succeeded and others ended as a report of failed attempts. That is the same failure-and-retry loop any developer knows from agentic coding, transplanted onto a victim’s network.

The operator also imposed the same three operational-security constraints at every victim, in Russian, repeatedly: no DCSync, restated in at least five messages as categorically forbidden; no account lockouts, attached to every password-spray or guessing request; and no adding new computer objects to the domain. Whoever this was understood that those three actions are what gets an intrusion caught, and drilled the agent on them like a checklist.

A Linux Encryptor Built for ESXi

The report’s other half is a Linux variant of the Aurora ransomware, recovered as a 139 KB ELF binary hosted on Cloudflare R2 and copied manually onto multiple internal hosts in a victim environment. It encrypts files in place with ChaCha20, wrapping each session key with an embedded RSA-4096 public key, and it carries a dedicated ESXi mode.

In that mode the encryptor enumerates running virtual machines with esxcli, force-kills each guest to release locks on virtual disk files, then encrypts VM files while skipping the hypervisor’s system volumes — deliberately leaving the host bootable so the victim can read the ransom demand. It also writes the extortion text into the SSH login banner, so anyone connecting to the machine sees the demand before the login prompt. A custom NetExec LDAP module, esxi_finder.py, scanned victim networks for ESXi hypervisors and vCenter servers, fingerprinting exact builds over TLS. Gambit published file hashes, command-and-control addresses, SOCKS proxy infrastructure, and the group’s negotiation portal and clearnet leak site as indicators of compromise.

A Second Cluster With Different Tradecraft

Gambit also attributes a second activity cluster to an Aurora operator with medium confidence, possibly a different person. The link is an exfiltration bucket that received data from an organization Aurora published on its leak site nine days later. This cluster spans eight victim organizations across Israel, Germany, Austria, Spain, the United States, and Argentina, and it skips the caution of the first: lateral movement through exposed SQL Server xp_cmdshell, escalation to SYSTEM with GodPotato, DCSync against the domain controller, and exfiltration with s5cmd to self-hosted S3-compatible storage. The contrast matters: one operator avoiding DCSync religiously while another runs it suggests a crew with uneven discipline rather than a single playbook.

The AI-Assisted Intrusion Pattern Is Recurring

Gambit has been tracking this shape of intrusion for months. Its April 10, 2026 technical report documented a single operator running two AI platforms against nine government agencies, and its August 2026 research on AI across the intrusion lifecycle mapped how AI assistance is spreading through each phase of real-world attacks. The Black Kite 2026 ransomware report similarly describes a faster, more fragmented threat economy. The Aurora logs are the most granular public evidence yet of what that looks like at the keyboard: not AI generating malware, but AI as an always-available exploitation consultant that lowers the skill floor for hands-on network intrusion.

The disclosure also lands at an awkward moment for the tool’s new owner. Cursor — which bills itself as the coding agent “for building ambitious software,” its own site says — formally became part of SpaceX on August 14, 2026, closing a $60 billion acquisition two weeks before the report’s publication. Gambit’s findings do not allege any failure in Cursor’s systems; the agent appears to have been a paid or otherwise ordinary tool, abused through ordinary access. The record Gambit published now gives defenders concrete infrastructure to block and hunt against, and gives the industry a documented case of an agentic coding product run end-to-end as attack tooling.

Credit: Source link

ShareTweetSendSharePin

Related Posts

Visa ships a security AI that patches production code before any human reviews it
AI & Technology

Visa ships a security AI that patches production code before any human reviews it

August 27, 2026
Live Updates From The Launch Of The Next S26
AI & Technology

Live Updates From The Launch Of The Next S26

August 27, 2026
Google Research Introduces GlucoFM: A 0.72M-Parameter Dual-Stream Foundation Model for Continuous Glucose Monitoring
AI & Technology

Google Research Introduces GlucoFM: A 0.72M-Parameter Dual-Stream Foundation Model for Continuous Glucose Monitoring

August 27, 2026
GLM-5.3-Flash will likely handle 45% of your AI workloads
AI & Technology

GLM-5.3-Flash will likely handle 45% of your AI workloads

August 27, 2026
Next Post
Viral video of Jersey Shore pizzeria refusing to cut a birthday cake triggers backlash

Viral video of Jersey Shore pizzeria refusing to cut a birthday cake triggers backlash

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Crowley thanks supporters after winning Democratic primary for Wisconsin governor

Crowley thanks supporters after winning Democratic primary for Wisconsin governor

August 25, 2026
Giving birth in Sudan in the world’s worst humanitarian crisis

Giving birth in Sudan in the world’s worst humanitarian crisis

August 23, 2026
Unitree Robotics Surges in Shanghai Debut

Unitree Robotics Surges in Shanghai Debut

August 20, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!