Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims
Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant (TL-2026-2165) is a high-severity ransomware operation, first published 2026-08-27. It is attributed to Aurora ransomware affiliate (Russia) with high confidence, affects Microsoft Active Directory Certificate Services, references 1 CVE (CVE-2017-0144), maps to 17 MITRE ATT&CK techniques (T1018, T1021.006, T1078.002), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-2165
- Threat ID
- TL-2026-2165
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-08-27
- Last reviewed
- 2026-08-27
- Attribution
- Aurora ransomware affiliate
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, industrial, food and agriculture, distribution, pharmacy, chemical, professional services, financial services, transport and logistics, consumer goods, waste management, it and backup infrastructure
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant
Malware and tooling: Aurora, Aurora Ransomware, BloodHound - S0521, Certipy, Chisel, John the Ripper, Kerbrute, NetExec, PKINITtools, evil-winrm, hashcat, metasploit
A Russian-speaking Aurora ransomware affiliate used the Cursor agentic coding assistant in Russian to draft and iteratively refine Active Directory Certificate Services (ADCS) exploitation plans between April and July 2026, compromising 20+ organizations across 9 countries with a repeatable playbook of AD enumeration, NTLM relay coercion, ADCS template abuse, and Kerberoasting, then deploying a Zig-based Windows/Linux/ESXi encryptor and laundering proceeds through hub-based cryptocurrency clustering infrastructure.
How Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant works
CloudSEK, in partnership with TRM Labs for on-chain payment tracing, documented a Russian-speaking Aurora ransomware affiliate operating as a direct operator (not an access broker) across a tracked three-month window (April-July 2026). The affiliate compromised 20+ organizations across 9 countries, achieving domain-level access at 17 of them and landing 4 on the public Aurora Tor leak site, with time-to-extortion ranging from 2 weeks to 2 months post-compromise. All operator infrastructure was fronted through rented SOCKS pivots on German and US VPS providers, so operator IPs never directly touched victim networks.
The affiliate's tradecraft was methodical and consistent across engagements: NetExec-driven LDAP/SMB enumeration (password policy retrieval, ASREPRoasting, Kerberoasting) followed by one of three privilege-escalation paths tailored per target -- a custom-scripted noPac chain (machine-account rename, TGT generation, S4U2self), ADCS certificate template misconfiguration abuse (ESC1, ESC6, ESC8) to mint domain-administrator certificates, or NTLM relay via coercion techniques (PetitPotam, PrinterBug, DFSCoerce). Credential harvesting extended to Kerberos ticket extraction (krbtgt captured in multiple cases), a custom seven-browser credential-theft module, and SSL-VPN credential validation. Lateral movement relied on evil-winrm, chisel, and proxychains; post-exploitation mapping used BloodHound; and in at least one case the affiliate reused the legacy EternalBlue (MS17-010) SMBv1 exploit for direct account creation. Data was staged for exfiltration via PowerShell-driven 7-Zip archiving in 50GB chunks before deployment of the encryptor, which was delivered to victim environments via a Cloudflare R2 bucket and scp.
The most novel element is the affiliate's sustained, Russian-language use of the Cursor agentic coding assistant to draft full ADCS exploitation plans, with unusually intensive iterative back-and-forth in the campaign's final weeks -- output that was written entirely in Russian rather than translated, indicating native-language use of the tool as a planning aid rather than a language-translation crutch. This mirrors a broader 2025-2026 trend of financially motivated actors weaponizing agentic coding assistants (Claude Code, Cursor) for reconnaissance, exploitation planning, and extortion workflows.
The encryptor itself is a single Zig codebase statically compiled to Windows (sap.exe), Linux, and ESXi targets -- a language choice that yields dependency-free static binaries with limited existing signature coverage. The Windows variant performs an anti-recovery chain (volume shadow copy deletion with storage resizing, System Restore disablement via registry, Hyper-V detection, backup-privilege enablement) before encryption. The Linux/ESXi variant (encrypt.out) enumerates and force-kills running VMs pre-encryption, targets VM-specific file types (vmdk, vmx, vmsd, vmsn, nvram, vmem, vswp, log), explicitly excludes ESXi system volumes, and delivers its ransom note via SSH login-banner modification rather than a dropped file. Both variants share a configurable CLI (-path, -percent<N> for partial-file encryption, -f<N><K|M|G> file-size filtering, -threads/-scanners, -extensions on Windows, -allowfolders on Linux) and embed a ransom note matching Aurora's published note character-for-character.
TRM Labs' independent on-chain analysis identified a traced wallet holding roughly 7 BTC, two confirmed and two high-moderate-confidence victim payments, and per-victim affiliate/operator revenue splits that varied widely (35/65, 21/79, 46/54, 40/60) rather than following a fixed ratio. Laundering flowed through two dominant hub-based consolidation clusters where affiliate and operator shares appear deliberately commingled before cash-out, alongside one isolated sequential peeling chain that bypassed hub consolidation entirely.
Attribution to a Russian-speaking operator is assessed with high confidence based on consistent Russian-language artifacts across all custom tooling, Cursor planning sessions, and a private GitLab repository of custom NetExec modules -- combined with a deliberate absence of CIS-allocated IP ranges or CIS-country domains in targeting across the full three-month window, corroborated by direct HUMINT engagement. Victim sectors were opportunistic rather than industry-focused, spanning manufacturing/industrial (largest share), food/agriculture/distribution, pharmaceutical/chemical, professional/financial services, transport/logistics, consumer goods, waste management, and IT/backup infrastructure, with the United States representing the largest single-country share.
MITRE ATT&CK techniques used in TL-2026-2165
Discovery
T1018 Remote System Discovery; T1087.002 Domain Account
Lateral Movement
T1021.006 Windows Remote Management
Privilege Escalation
Command and Control
Impact
T1489 Service Stop; T1490 Inhibit System Recovery; T1491.001 Internal Defacement; T1657 Financial Theft
Credential Access
T1555.003 Credentials from Web Browsers; T1557.001 Name Resolution Poisoning and SMB Relay; T1558.001 Golden Ticket; T1558.003 Kerberoasting; T1558.004 AS-REP Roasting; T1649 Steal or Forge Authentication Certificates
Collection
Resource Development
Affected products and versions in Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant
- Microsoft — Active Directory Certificate Services
Vulnerable versions: environments with misconfigured ESC1/ESC6/ESC8 certificate templates or CA settings
Fixed in: environments hardened per Microsoft ADCS security guidance - Microsoft — Windows Server / SMBv1 (MS17-010 EternalBlue)
Vulnerable versions: legacy, unpatched hosts with SMBv1 enabled
Fixed in: hosts patched per MS17-010 (March 2017) - VMware — ESXi
Vulnerable versions: ESXi hosts reachable by the affiliate's Linux/ESXi Zig encryptor variant (encrypt.out)
Remediation for Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant
Patches
- Apply MS17-010 (March 2017) to any remaining Windows hosts vulnerable to EternalBlue
Immediate actions
- Disable LLMNR and NBT-NS name resolution to close the NTLM relay coercion paths abused via PetitPotam, PrinterBug, and DFSCoerce
- Audit ADCS certificate templates and CA configuration for ESC1 (enrollee-supplied subject), ESC6 (EDITF_ATTRIBUTESUBJECTALTNAME2), and ESC8 (NTLM relay to web enrollment) misconfigurations
- Rotate the krbtgt account password twice, per Microsoft guidance, given confirmed krbtgt ticket extraction in multiple victim environments
- Audit Service Principal Names and rotate associated service-account credentials to blunt Kerberoasting
Workarounds
- Disable SMBv1 entirely where MS17-010 patching cannot be applied immediately
- Restrict or require HTTPS+Extended Protection for Authentication on the ADCS web enrollment (certsrv) HTTP endpoint to blunt ESC8 NTLM relay
Longer-term hardening
- Retire or isolate legacy Windows hosts still exposed to MS17-010 (EternalBlue) SMBv1 remote code execution
- Harden and air-gap/immutable-protect backup infrastructure against Inhibit System Recovery techniques (volume shadow copy deletion, System Restore disablement, backup-privilege abuse)
- Deploy browser credential-store protections (e.g., App-Bound Encryption, EDR browser-credential guards) against the affiliate's seven-browser harvesting module
- Monitor for anomalous, high-volume agentic AI coding-assistant usage patterns as a reconnaissance/planning signal
CVEs associated with Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant
Timeline of Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant
- Tracked activity window begins: a Russian-speaking Aurora ransomware affiliate opens a three-month campaign (April-July 2026) with NetExec-driven LDAP/SMB enumeration against the first of eventually 20+ victim organizations across 9 countries, staged entirely through rented German and US VPS SOCKS pivots.
- Across the campaign the affiliate achieves domain-level access at 17 of the 20+ compromised organizations via a repeatable playbook of Kerberoasting/ASREPRoasting, the noPac machine-account-rename chain, ADCS template abuse (ESC1/ESC6/ESC8), and NTLM relay coercion (PetitPotam/PrinterBug/DFSCoerce).
- In the final weeks of the tracked window, the affiliate's use of the Cursor agentic coding assistant intensifies into sustained, iterative Russian-language sessions drafting and refining full ADCS exploitation plans.
- Tracked campaign activity window closes; over the period, 4 of the 20+ compromised victims are publicly listed on the Aurora Tor leak site, with time-to-extortion ranging from 2 weeks to 2 months post-compromise.
- CloudSEK publishes "The Aurora Files," detailing the affiliate's AI-assisted ADCS attack planning, Zig-based Windows/Linux/ESXi encryptor, and hub-based cryptocurrency laundering infrastructure.
- CloudSEK, working with TRM Labs for independent on-chain payment tracing, notifies relevant national CERTs and non-public victims ahead of public disclosure.
Sources cited for Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant
- Aurora Ransomware Affiliate: AI-Assisted Attack Planning and Crypto Payment Tracing ("The Aurora Files")
- Obtain Capabilities: Artificial Intelligence, T1588.007
- Financial Theft, T1657
- CVE Record: CVE-2017-0144 (EternalBlue / MS17-010)
- MS17-010 EternalBlue SMB Remote Windows Kernel Pool Corruption
- Certipy Wiki: Privilege Escalation (ESC1-ESC8 ADCS abuse paths)
- Agentic AI coding assistant helped attacker breach, extort 17 distinct organizations
- Aurora Ransomware Breach Tracker
- Group: aurora
More in ransomware
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas
- KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Software
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices
Detection coverage for TL-2026-2165
As of 2026-08-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2165 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2165
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.