The record
Written from the 1 report below. Nothing here is unsourced.
- Researchers at CloudSEK and Gambit Security found that the Aurora ransomware group used the AI coding assistant Cursor to plan and help execute attacks on more than 20 organizations across nine countries between April and July 2026.
- The findings come from the group's own exposed infrastructure, which leaked chat histories, tools, and encryption software showing the AI assistant was given tasks like scanning networks, checking user privileges, and carrying out exploitation steps.
- Aurora attacks typically start with email bombing and fake IT help desk calls, followed by spreading within networks, stealing data, and deploying encryptors for both Windows and Linux/ESXi systems.
- The case highlights how commercial AI tools are increasingly being used by cybercriminals, and a new AI-assisted toolkit called Gryxa has also been discovered.
What to watch next
- Whether named victims such as Christeyns, Teckentrup, and Bayou Title face data leaks on Aurora's leak site.
- How AI providers like Cursor and Anthropic respond to or restrict misuse of their tools by threat actors.
- Further details on the newly discovered Gryxa AI-assisted toolkit and its use in attacks.
Coverage1
1 report
English national1
All filed from India
Named United States · Germany · Netherlands · Canada · United Kingdom · Argentina · Italy · Bayou Title · Christeyns · Helideck Certification Agency · SpaceX · Teckentrup · Aurora · Black Hills Information Security · CloudSEK · Cursor · CYFIRMA · Eyal Sela · Gambit Security
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
