# A ransomware crew ran Cursor inside ten victim networks

> An Aurora affiliate drove the Cursor coding agent through ten victim networks this spring. The victim list looks like ordinary European industry.

Source: https://fmcybersecurity.com/en/insights/ai-security/aurora-ransomware-cursor-agent/
Locale: English
Other locale: https://fmcybersecurity.com/insights/ai-security/losepengeoperator-kjorte-cursor-i-ti-offernettverk/

## Metadata

- Date: 2026-09-01
- Author: christian-vik
- Topic: ai-security
- Format: news
- Scope: international

The operator behind at least ten network intrusions this spring did not bring custom attack tooling. They brought Cursor, a commercial AI coding assistant, and let it do the hands-on work.

## What the reports show

On August 27 CloudSEK published [an analysis of an exposed server](https://www.cloudsek.com/blog/aurora-ransomware-affiliate-ai-attack-planning-crypto-payments) belonging to an affiliate of the Aurora ransomware operation. A misconfigured directory laid out the operator's toolkit, shell history and attack plans, covering April through July 2026. The files point to more than 20 compromised organizations across nine countries, with domain-level or interactive access in 17 of them. Four have since appeared on Aurora's leak site.

The same exposure let Gambit Security reconstruct how the intrusions ran, [per Infosecurity Magazine](https://www.infosecurity-magazine.com/news/abuse-cursor-agent-ransomware/). In ten victim networks between April 8 and late May, the operator drove Cursor Agent, running Anthropic's Claude Sonnet model, through the intrusion work itself, [The Hacker News reports](https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html). The agent installed VPN clients and proxychains, mapped subnets with Nmap and NetExec, collected Active Directory data for BloodHound, and ran NTLM relay and certificate attacks with Certipy. Gambit's threat intelligence director Eyal Sela describes the sessions as ["a junior intruder working a shift with a senior engineer on call"](https://oodaloop.com/briefs/cyber/ransomware-operator-ran-cursor-agent-inside-ten-victim-networks/).

Look at the victim list before you file this as someone else's problem. Christeyns is a Belgian industrial chemicals group. Teckentrup makes doors in Germany. The recovered attack plans were written in Russian, excluded CIS targets without exception, and leaned toward manufacturing and food companies. This crew hunts the European mid-market, and a coding agent did the typing.

The ransomware itself stayed conventional. CloudSEK found a Zig-written encryptor with an ESXi variant that kills virtual machines before encrypting and leaves its ransom note in the SSH banner. Most of the agent's commands failed on the first attempt, Gambit notes, and went through "multiple refinements" before they landed.

We reported in August that [97 percent of AI-written malware never left the sandbox](/en/insights/ai-security/ai-malware-97-percent-never-left-the-sandbox/). That finding still holds. This story shows where AI reached production intrusions anyway: in the operator's chair, for the price of a coding-tool subscription. That is the scaling mechanism we described when [open models made offensive work cheaper](/en/insights/ai-security/prepare-for-ai-driven-hacking/).

## What you do about it

The agent typed the same commands human intruders type. Nmap sweeps, NetExec sessions, NTLM relay and Certipy runs land in endpoint and identity telemetry no matter who issues them. Every failed retry is one more chance to alert. Detection did not get harder here. The window got shorter, because the operator iterates at machine speed. If those techniques would pass unseen in your network today, that gap comes before any AI-specific control.

I find coding agents in nearly every development stack we review. Cursor showing up in attacker logs does not make it malware, it makes it dual-use. Banning it outright mostly produces unmanaged installs, so treat it like the rest of your tooling instead: know which agents run where, what credentials they hold, and what they can reach. In our [AI security work](/en/services/ai-security/) that inventory is the first deliverable, and after this report it belongs in your threat model too.

Talk to Christian Vik if you want our read on what AI-assisted intrusion changes for your detection stack.

Drafted with AI assistance, reviewed and edited by Christian Vik and the FM editorial team.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
