Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims — Threadlinqs Intelligence
As of 2026-08-27, Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims is a high-severity ransomware threat attributed to Aurora ransomware affiliate (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-2165 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Aurora ransomware affiliate · Russia · FINANCIAL
A Russian-speaking Aurora ransomware affiliate used the Cursor agentic coding assistant in Russian to draft and iteratively refine Active Directory Certificate Services (ADCS) exploitation plans
CloudSEK, in partnership with TRM Labs for on-chain payment tracing, documented a Russian-speaking Aurora ransomware affiliate operating as a direct operator (not an access broker) across a tracked three-month window (April-July 2026). The affiliate compromised 20+ organizations across 9 countries, achieving domain-level access at 17 of them and landing 4 on the public Aurora Tor leak site, with time-to-extortion ranging from 2 weeks to 2 months post-compromise. All operator infrastructure was fronted through rented SOCKS pivots on German and US VPS providers, so operator IPs never directly touched victim networks.
The affiliate's tradecraft was methodical and consistent across engagements: NetExec-driven LDAP/SMB enumeration (password policy retrieval, ASREPRoasting, Kerberoasting) followed by one of three privilege-escalation paths tailored per target -- a custom-scripted noPac chain (machine-account rename, TGT generation, S4U2self), ADCS certificate template misconfiguration abuse (ESC1, ESC6, ESC8) to mint domain-administrator certificates, or NTLM relay via coercion techniques (PetitPotam, PrinterBug, DFSCoerce). Credential harvesting extended to Kerberos ticket extraction (krbtgt captured in multiple cases), a custom seven-browser credential-theft module, and SSL-VPN credential validation. Lateral movement relied on evil-winrm, chisel, and proxychains; post-exploitation mapping used BloodHound; and in at least one case the affiliate reused the legacy EternalBlue (MS17-010) SMBv1 exploit for direct account creation. Data was staged for exfiltration via PowerShell-driven 7-Zip archiving in 50GB chunks before deployment of the encryptor, which was delivered to victim environments via a Cloudflare R2 bucket and scp.
The most novel element is the affiliate's sustained, Russian-language use of the Cursor agentic coding assistant to draft full ADCS exploitation plans, with unusually intensive iterative back-and-forth in the campaign's final weeks -- output that was written entirely in Russian rather than translated, indicating native-language use of the tool as a planning aid rather than a language-translation crutch. This mirrors a broader 2025-2026 trend of financially motivated actors weaponizing agentic coding assistants (Claude Code, Cursor) for reconnaissance, exploitation planning, and extortion workflows.
The encryptor itself is a single Zig codebase statically compiled to Windows (sap.exe), Linux, and ESXi targets -- a language choice that yields dependency-free static binaries with limited existing signature coverage. The Windows variant performs an anti-recovery chain (volume shadow copy deletion with storage resizing, System Restore disablement via registry, Hyper-V detection, backup-privilege enablement) before encryption. The Linux/ESXi variant (encrypt.out) enumerates and force-kills running VMs pre-encryption, targets VM-specific file types (vmdk, vmx, vmsd, vmsn, nvram, vmem, vswp, log), explicitly excludes ESXi system volumes, and delivers its ransom note via SSH login-banner modification rather than a dropped file. Both variants share a configurable CLI (-path, -percent<N> for partial-file encryption, -f<N><K|M|G> file-size filtering, -threads/-scanners, -extensions on Windows, -allowfolders on Linux) and embed a ransom note matching Aurora's published note character-for-character.
TRM Labs' independent on-chain analysis identified a traced wallet holding roughly 7 BTC, two confirmed and two high-moderate-confidence victim payments, and per-victim affiliate/operator revenue splits that varied widely (35/65, 21/79, 46/54, 40/60) rather than following a fixed ratio. Laundering flowed through two dominant hub-based consolidation clusters where affiliate and operator shares appear deliberately commingled before cash-out, alongside one isolated sequential peeling chain that bypassed hub consolidation entirely.
Attribution to a Russian-speaking operator is assessed with high confidence based on consistent Rus
Target sectors: manufacturing, industrial, food and agriculture, distribution, pharmacy, chemical, professional services, financial services, transport and logistics, consumer goods, waste management, it and backup infrastructure
Target regions: North America, Europe
Timeline
- Tracked activity window begins: a Russian-speaking Aurora ransomware affiliate opens a three-month campaign (April-July 2026) with NetExec-driven LDAP/SMB enumeration against the first of eventually 20+ victim organizations across 9 countries, staged entirely through rented German and US VPS SOCKS pivots.
- Across the campaign the affiliate achieves domain-level access at 17 of the 20+ compromised organizations via a repeatable playbook of Kerberoasting/ASREPRoasting, the noPac machine-account-rename chain, ADCS template abuse (ESC1/ESC6/ESC8), and NTLM relay coercion (PetitPotam/PrinterBug/DFSCoerce).
- In the final weeks of the tracked window, the affiliate's use of the Cursor agentic coding assistant intensifies into sustained, iterative Russian-language sessions drafting and refining full ADCS exploitation plans.
- Tracked campaign activity window closes; over the period, 4 of the 20+ compromised victims are publicly listed on the Aurora Tor leak site, with time-to-extortion ranging from 2 weeks to 2 months post-compromise.
- CloudSEK, working with TRM Labs for independent on-chain payment tracing, notifies relevant national CERTs and non-public victims ahead of public disclosure.
- CloudSEK publishes "The Aurora Files," detailing the affiliate's AI-assisted ADCS attack planning, Zig-based Windows/Linux/ESXi encryptor, and hub-based cryptocurrency laundering infrastructure.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2017-0144, T1588.007, T1087.002, T1018, T1558.004, T1558.003, T1558.001, T1555.003, T1649, T1557.001, T1078.002