Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Ransomware Affiliate Used AI Coding Tool Cursor to Plan Attacks on 20+ Companies Across 9 Countries
Ransomware Affiliate Used AI Coding Tool Cursor to Plan Attacks on 20+ Companies Across 9 Countries
Read Time:3 Minute, 21 Second

Researchers at CloudSEK, with payment-tracing support from TRM Labs, have reconstructed one of the clearest pictures yet of how ransomware operators are folding AI coding assistants into their day-to-day workflow, after a misconfigured staging server used by a Russian-speaking Aurora ransomware affiliate was left exposed to the open internet.

An Exposed Server Opens a Window Into the Operation

The directory investigators found wasn’t sanitized or hidden — it contained the affiliate’s working toolkit, command history, credential material gathered from victims, chat logs from the Cursor AI coding assistant, and a copy of the Aurora encryptor itself. That combination let researchers reconstruct not just what the attacker did, but how they thought through it, since the Cursor chat history captured back-and-forth planning sessions rather than a single generated command.

How AI Fit Into the Attack Chain

The operator used Cursor to draft and refine attack sequences, conducting at least one extended session focused specifically on exploiting Active Directory Certificate Services (AD CS) misconfigurations — a well-known but still commonly overlooked privilege escalation path in Windows environments. Notably, the conversations were conducted in Russian, and researchers describe the pattern as iterative planning: the human operator posing problems and refining next steps with the AI’s help, rather than simply pasting in a ready-made exploit. It’s a reminder that the risk from AI-assisted attacks right now looks less like fully autonomous hacking and more like a skilled operator working faster and with fewer knowledge gaps.

Scope and Scale of the Campaign

Between April and July 2026, the affiliate targeted more than 20 organizations spread across nine countries, concentrated in manufacturing, food and agriculture, and professional services. Of those targets, 17 reportedly reached the stage of interactive domain access — meaning the attacker had established a meaningful foothold inside the victim’s Active Directory environment — and four victims ultimately had their names posted to Aurora’s public extortion leak site, the pressure tactic ransomware groups use to push non-paying victims toward negotiation.

The Technical Playbook

The reconstructed intrusion chain followed a methodology that will look familiar to defenders who track ransomware affiliates, even with AI in the loop:

  • Establishing SOCKS proxy tunnels to route traffic through compromised infrastructure
  • Conducting internal network discovery using tools such as NetExec
  • Harvesting credentials via ASREPRoasting and Kerberoasting attacks against Active Directory accounts
  • Escalating to domain compromise by abusing certificate services and relaying NTLM authentication
  • Deploying the Aurora encryptor once sufficient access and visibility had been established

None of these individual techniques are new — AD CS abuse, Kerberoasting, and NTLM relay have all been staples of ransomware intrusions for several years. What’s notable is the role an AI coding assistant played in helping the operator plan and sequence them, particularly for someone working through the more involved certificate-abuse steps.

What This Means for Defenders

This case adds to a growing body of evidence that ransomware crews are treating AI coding tools as productivity software rather than novelty, using them the way a legitimate developer would use a pair-programming assistant — to work through unfamiliar technical terrain faster. For defenders, the underlying detections don’t change much: monitoring for ASREPRoasting and Kerberoasting activity, auditing AD CS templates for common misconfigurations, and watching for anomalous SOCKS proxy traffic remain effective regardless of whether the human behind the keyboard had an AI assistant open in another window. The bigger shift is one of speed and accessibility — techniques that once required deep specialist knowledge are becoming easier for a broader range of affiliates to execute competently.

It’s also a useful reminder for the AI vendors themselves. Cursor and similar coding assistants are general-purpose tools with no reliable way to distinguish a penetration tester’s legitimate Active Directory research from a ransomware affiliate doing the same thing in Russian at 2 a.m. Absent better abuse-detection signals on the AI tooling side, the practical burden of defense continues to fall on the network and identity monitoring that would have caught this intrusion chain regardless of how the attacker planned it.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Ransomware Affiliate Used AI Coding Tool Cursor to Plan Attacks on 20+ Companies Across 9 Countries, use the discussion on Forum.

>> forum community

Comments

Leave a Reply