# Researchers link Aurora ransomware activity to Cursor AI agent use

_Monday, August 31, 2026 at 7:47 AM EDT · Security, AI · Latest · Tier 1 — Major_

![Researchers link Aurora ransomware activity to Cursor AI agent use — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHyB4qaQy8srcEIgc1oMi08PMKtoVFIsmW3ho_7f7rISFML8Kmz8jYzDE1FCN9Nfo4LvvgVFV_FEijgLbCrZcJ5zy7xlvAYTKuyGrcE0IU6yqEd-awlmOyRQ3FXcSeA5yM71NLDa5nxpj9taGnNiVXvCb_5tun5j3dfb6z8j7cmwQ2O0PE2V3y0oKWv6sB/s1700-nu-rw-lo-l85-e365/cursor.jpg)

CloudSEK and Gambit Security reported that operators associated with Aurora ransomware used Cursor's agentic coding tools while working against victim networks. Gambit said it observed Cursor Agent running Anthropic's Claude Sonnet during hands-on exploitation of 10 targets between April 8 and May 21. Recovered activity described tasks including internal scanning, privilege enumeration, NTLM relay attempts and certificate attacks. The reports say many commands did not achieve their objectives on the first try and were refined by the operators.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html)

---
Canonical: https://techandbusiness.org/newswire/9dtZ2C8CBeuc4KqWB-Q2u0
Retrieved: 2026-08-31T18:08:52.055Z
Publisher: Tech & Business (techandbusiness.org)
