Threat-intelligence firm CloudSEK reported August 27 that a ransomware affiliate tied to the Aurora operation used Cursor -- an agentic AI coding assistant -- as a hands-on tool for planning and executing real attacks against more than 20 organizations across nine countries between April and July 2026. Rather than writing malware, CloudSEK says the operator supplied Cursor with live stolen credentials or existing network access, then directed the agent to perform reconnaissance, assess privilege levels, scan internal systems, and draft a detailed Active Directory Certificate Services exploitation plan -- conducting the back-and-forth entirely in Russian.
CloudSEK, which says it recovered the operator's chat logs from an exposed directory, describes a Russian-speaking affiliate operating independently rather than selling access to others -- deploying the ransomware itself and negotiating separate revenue splits per victim (ranging from 21/79 to 46/54) instead of a fixed affiliate cut. The operator's targeting excluded CIS-allocated IP ranges and CIS-country domains without exception, a pattern common among Russian-speaking cybercrime groups avoiding domestic law enforcement attention. Of the 20-plus organizations CloudSEK says were compromised -- concentrated in manufacturing, food and agriculture, pharmaceutical distribution and logistics, with the United States the largest share -- only four subsequently appeared on Aurora's public leak site.
- Supplies Cursor with stolen credentials or an existing foothold in the victim's network
- Runs reconnaissance and scans the environment for privilege-escalation paths
- Drafts a step-by-step Active Directory Certificate Services exploitation plan, in Russian
- Executes the plan by hand, installs a VPN client, runs the certificate attack
- Deploys the encryptor directly, without a broker or reseller
CloudSEK's own recommendations are specific rather than generic: disable LLMNR and NBT-NS network protocols, enforce SMB signing, audit Active Directory Certificate Services templates for the ESC1/ESC6/ESC8 misconfigurations the operator is described as exploiting, rotate krbtgt passwords twice across a full replication interval, and isolate backup infrastructure on separate credentials. None of that is Cursor-specific -- the report frames the AI agent as a force multiplier for an attacker's own technical planning, not as the source of the vulnerabilities it was used to find.
- CloudSEK says an Aurora ransomware affiliate used Cursor's AI agent to plan real attacks.
- The operator fed Cursor live credentials, then had it run recon and exploitation planning.
- 20-plus organizations across nine countries were compromised between April and July 2026.
- The operator worked in Russian and explicitly excluded all CIS-region targets.
- Caveat: this is one security firm's report; Cursor's maker has not published its own account.