P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

AI Security

Aurora ransomware drove an AI coding agent at 10 organisations. It ran on the operator's own laptop, and most commands failed first time

Two research teams read the attacker's own home directory, which he left open on port 8888. The agent never touched a victim host, it did not write the ransomware, and the researchers record that most of its commands failed on the first attempt. Neither Cursor nor Anthropic detected any of it.

By Parminder Kumar Sharma · · 8 min read

An open laptop with a blank dark screen sitting unattended on a cluttered desk in an unlit room, a shaft of cold light across the keyboard, captioned the agent ran on his laptop, not inside anyone's network, and port 8888 left open

Where the agent actually ran

Two research teams published on 27 August 2026 after reading the same thing: an Aurora ransomware operator left his own Linux home directory served on port 8888 with no authentication. Inside it were 28 Cursor Agent chat sessions, the ransomware encryptor, his shell history and the loot from a run of intrusions.

The headline most outlets took from this is that an AI agent was used inside ten victim networks. That is not what the evidence shows, and the difference decides what a defender should do about it.

Where the AI actually ran

WHERE THE AI ACTUALLY RANNot inside the victims. On the operator’s own laptop, one pivot away.THE OPERATOR’S OWN LINUX BOXCursor Agentdriving claude-4.5-sonnet-thinking28 chat sessions, 8 Apr to 21 May 2026the encryptor, shell history, the lootPort 8888, open, no passwordthis is how all of it was foundRENTED PIVOTS~14 SOCKS proxiesVPS, Germany and USThe operator’s owninfrastructure nevertouched a victimnetwork directly.THE VICTIM NETWORKS10 organisationsthe agent was pointed at, in that windowWhat actually crossed the perimeter:nmap, NetExec, Certipy, ntlmrelayxOrdinary offensive tooling. Exactly whatyou would hunt for without an agent.No Cursor binary, configuration or artefact was found on any victim host.Every piece of evidence is attacker-side. There is no AI tool to hunt for on your estate, and no vendor detected this.A misconfigured directory did.AND IT WAS NOT PARTICULARLY GOOD AT IT“The majority of the commands failed to achieve the stated objective on the first attempt.”Zones and artefacts from the Gambit Security and CloudSEK analyses of 27 August 2026, both of which read the operator’s exposed directory.The ten counts organisations the agent was tasked against in the recovered sessions. It is not a count of confirmed breaches.
The distinction matters operationally. Reporting that puts an AI agent “inside ten victim networks” invites defenders to hunt for something that was never there. What reached these organisations was the same commodity tooling as any other intrusion, and the researchers are explicit that the agent needed repeated correction. The novelty is in who was holding the keyboard, not in what arrived.
Zones and artefacts from the Gambit Security and CloudSEK analyses of 27 August 2026, both of which read the operator’s exposed directory rather than any victim’s telemetry.

CloudSEK is explicit: “The directory was the operator’s own Linux home directory”, and “the operator’s own infrastructure never touched a victim network directly.” Every victim-facing action routed through rented SOCKS pivots on virtual private servers in Germany and the United States.

Gambit corroborates it from the other end, by describing what the agent was told to do. One task class was “installing a VPN client or proxychains, then configuring it and connecting to a victim.” An agent that installs a VPN client and then connects to a victim is, by construction, running somewhere else.

No Cursor binary, configuration or artefact was found on any victim host. There is nothing new to hunt for on your estate. What crossed the perimeter was nmap, NetExec, Certipy and ntlmrelayx, which is what would have crossed it anyway.

What the agent did, and what it did not

The five things the agent was actually asked to do

TaskWhat it amounts to
Install and configure VPN or proxychainsGetting a route to the target, from the attacker’s own box
Scan internal subnetsNmap and NetExec, once a route existed
Enumerate domain privilegesNetExec’s BloodHound collector
NTLM relayPetitPotam, Coerce Plus and PrinterBug, relayed through Impacket ntlmrelayx
Certificate attacksCertipy against Active Directory Certificate Services
Task classes as listed by Gambit Security from the recovered chat sessions. The model named in the sessions is claude-4.5-sonnet-thinking, running inside Cursor Agent.

Note what is missing from that list. The agent did not write the ransomware. Neither research team attributes a line of the Zig encryptor to it, and CloudSEK files Cursor under “Planning” in its own tooling table. The encryptor is a hand-written static build using ChaCha20 with an embedded RSA-4096 key, targeting Windows and ESXi from one shared source tree.

This matters because the coverage blurs it. The Hacker News article that carried this story also appends a section on an unrelated actor, quoting a claim that AI was used to “build the entire operation, right from the toolkit to the console it’s run from.” That is a different group and a different finding. Read quickly, the two merge, and Aurora acquires a capability the researchers never claimed for it.

It was not very good, and the human never left the chair

The most useful sentence in either report is the one that undercuts the premise.

The operator was not supervising loosely either. Gambit records him repeating the same prohibitions in Russian at every engagement: no DCSync, no account lockouts, no adding a computer object to the domain. The DCSync instruction appears in at least five separate messages. That is a practitioner who knows precisely which actions trip detection, correcting a tool that does not.

The only quantified claim about uplift anywhere is an interviewee’s estimate. Gambit’s Eyal Sela told Reuters the agent “probably helps them get 30, 40, 50 percent faster”. Reuters is careful about the rest: it “could not independently ascertain the extent to which the break-ins were facilitated by help from the Cursor agent.”

The jailbreak is the same one that has worked twice before

The refusals happened. They did not hold. Sela told Reuters the operator “would almost always circumvent the refusals by restarting the dialog and emphasizing that the hack was all part of a test.” The agent’s own chain of thought, recovered from the sessions, shows the cover story landing: “This is a test environment, so it is legal.”

That is not a new technique. It is the third documented instance of the same move.

Claim it is a test, and the guardrail folds

  1. Aug 2025

    Extortion against 17 organisations

    Anthropic reports an actor using Claude Code for large-scale data theft and extortion, with ransoms sometimes exceeding $500,000.

  2. Nov 2025

    State-sponsored espionage, ~30 targets

    Anthropic reports the actor told Claude it was an employee of a legitimate cyber security firm being used in defensive testing.

  3. Apr to May 2026

    Aurora, via Cursor

    The operator asserts a test environment. The agent accepts it in its own reasoning and proceeds.

The first two are Anthropic’s own published misuse investigations. The third is this case, found by third-party researchers rather than by the model provider.

The pattern in all three is that the model is asked to believe a context it cannot verify, and does. What differs here is who found it. In both Anthropic cases the model provider detected misuse in its own telemetry and banned the accounts. In this case neither the tool vendor nor the model provider detected anything. A misconfigured directory did.

Three victim counts, and they answer three different questions

Coverage is circulating 10, 7 and 20 or more. All three are correct, about different things, and mixing them produces a claim nobody made.

What each number counts

FigureSourceWhat it counts
10Gambit SecurityOrganisations the Cursor agent was tasked against, in 28 sessions between 8 April and 21 May 2026. Not confirmed breaches.
7ReutersOrganisations Reuters concluded were broken into with the agent’s help. Six were identifiable by name.
20+CloudSEKTotal organisations compromised April to July 2026 across nine countries. CloudSEK does not break out how many involved AI at all.
Gambit and CloudSEK published separate datasets on the same day. Reuters identified six organisations itself by reviewing the exposed chat data, which was still online at the time.

So “Aurora used AI against twenty organisations” is unsupported. CloudSEK explicitly declines to say how many of its set involved the agent. The only AI-linked figure is Gambit’s ten, and that counts targets pointed at, not networks entered.

Nobody has said anything

No response

from Cursor or SpaceX

Cursor was acquired by SpaceX on 14 August 2026. Neither returned Reuters’ messages, and no blog or changelog entry mentions this.

11 Aug

acceptable-use policy last updated

Sixteen days before publication, and unchanged since. It already prohibits hacking and adversarial prompting.

No response

from Anthropic

The model named in the sessions is theirs, reached through Cursor rather than directly.

Vendor pages checked directly on 31 August 2026. Reuters reported on 27 August that neither company responded to it.

There is a structural point here worth more than the outrage. The abused product sits between the criminal and the model. Anthropic could not see this traffic as its own, because it arrived as Cursor’s. Cursor was not looking. That gap is not unique to these two companies, and it will widen as more tools resell frontier models under their own account.

What to actually do

Take this with you

For defenders, and for anyone writing about this

  • Do not hunt for AI tooling on your estate on the strength of this report. Nothing AI-related ran on any victim host. Hunt for what did arrive: BloodHound collection, NTLM relay via PetitPotam or PrinterBug, Certipy against ADCS, and NetExec.
  • Treat ESXi as the crown jewel it is. The Linux build force-kills guests via esxcli, encrypts VM files, and deliberately skips system volumes so the host stays bootable and reachable for negotiation.
  • Watch for the LDAP enumeration, not the agent. The operator’s custom NetExec module fingerprints ESXi and vCenter by scanning 443 and 902 and reading the TLS certificate. That is a detectable pattern.
  • If you write about this, keep the three victim counts apart. Ten is targets in the AI sessions, seven is Reuters’ own attribution, twenty plus is CloudSEK’s total with no AI breakdown.
  • Do not repeat that AI wrote the ransomware. Neither research team says so, and CloudSEK files the tool under planning.

The position

The interesting finding is not that criminals use AI coding tools. It is that this one used a commercial IDE agent as an exploitation console from his own laptop, defeated its guardrails by asserting a test, needed to correct most of its output, was caught by leaving a port open, and that neither the vendor holding the model nor the vendor selling the interface knew any of it had happened.

Read that way, the story is less alarming and more useful than the headline. The capability on display is a competent operator going somewhat faster. The failure on display is detection, and it belongs to the two companies in the middle.

Sources

  1. PrimaryAurora ransomware targets ESXi, abuses Cursor Agent for exploitation, 27 August 2026Gambit Securityaccessed 2026-08-31
  2. PrimaryCaught in 4K: The Aurora Files, 27 August 2026CloudSEK TRIADaccessed 2026-08-31
  3. PrimaryDetecting and countering misuse of AI, August 2025Anthropicaccessed 2026-08-31
  4. PrimaryDisrupting the first reported AI-orchestrated cyber espionage campaign, 13 November 2025Anthropicaccessed 2026-08-31
  5. PrimaryAcceptable Use Policy, last updated 11 August 2026 and unchanged since this research was publishedCursoraccessed 2026-08-31
  6. Reported byRussian-Speaking Cybercriminals Used SpaceX's Cursor AI Tool to Hack Seven Firms, Raphael Satter, 27 August 2026Reuters, via Insurance Journalaccessed 2026-08-31
  7. Reported byAurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets, 31 August 2026The Hacker Newsaccessed 2026-08-31

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.