Aurora ransomware operator used Cursor Agent in 10 intrusions and targeted ESXi hosts
Gambit Security says an Aurora ransomware operator used Cursor Agent inside 10 victim networks and paired it with tooling to find and encrypt VMware ESXi environments.
According to Gambit Security, the operator used Cursor Agent, running Claude Sonnet, during hands-on activity across 10 organizations between April 8 and May 21, 2026. Gambit said the sessions started with credentials or an existing route into the network, then used the agent for internal scanning, VPN or proxy setup, privilege enumeration, NTLM relay attempts and certificate attacks. Gambit also reported that many agent commands failed on the first try and were sometimes retried with refined prompts or scripts.
Gambit said a custom NetExec module, esxi_finder.py, searched for ESXi hypervisors and vCenter servers by learning internal ranges, scanning ports 443 and 902, checking TLS certificates and fingerprinting product builds through web and SDK paths. ESXi is VMware’s hypervisor, and vCenter is its centralized management server. Gambit also documented a Linux Aurora encryptor with an ESXi mode that stopped running virtual machines, encrypted virtual-machine files and skipped system volumes so the host remained bootable. The report said the encryptor also wrote the ransom note into the host SSH banner.
Sources
- Gambit Security: Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation
- Infosecurity Magazine: Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
- Being Guru: Ransomware Crew Used Cursor AI Agent to Attack Networks
- NetNewsLedger: Exposed Aurora ransomware server reveals AI-assisted attacks, stolen credentials and crypto laundering