Cyber Security News

Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations

Aurora ransomware has been tied to a Russian-speaking affiliate that used an AI coding assistant while targeting more than 20 organisations.

A wrongly exposed server gave investigators a detailed view of the operator’s activity, from intrusion to payment. The activity ran from April to July 2026 across nine countries.

The operator gained domain-level or interactive access at 17 targets, while four victims appeared on Aurora’s public leak site. Manufacturing, food, agriculture and professional services were affected.

CloudSEK said in a report shared with Cyber Security News (CSN) that the exposed directory contained the affiliate’s tools, command history, credential material, Cursor chat records and Aurora encryptor.

The evidence points to an affiliate conducting intrusions, rather than a broker selling access. The findings show how ransomware operations can combine familiar Windows network abuse with faster planning support.

Open Directory (Source – CloudSEK)

The operator used rented SOCKS proxies to reach victim environments, then relied on tools for discovery, password attacks, credential theft, data theft and encryption-tool delivery.

Ransomware Hacker Uses AI

In its final weeks of recorded activity, the affiliate used Cursor to draft and refine attack sequences in Russian.

One extended session focused on exploiting weaknesses in Active Directory Certificate Services, a certificate-issuing feature, against a victim environment. The chats show back-and-forth planning rather than a generated command.

That matters because an assistant can help an intruder translate reconnaissance results into the next step quickly, even when the underlying tactics, such as those in AI-assisted ransomware operations, remain familiar to defenders.

The affiliate followed a repeatable playbook. It used NetExec to examine network services, retrieved password policy details, and attempted ASREPRoasting and Kerberoasting, techniques used to obtain password data for offline cracking. It also collected SAM and LSA information, Group Policy exports and BloodHound data.

The most heavily-worked AI-assisted engagement in the operator’s recovered chat history (Source – CloudSEK)

For deeper access, the operator used a custom noPac route, certificate-service abuse and NTLM relay attacks triggered with PetitPotam, PrinterBug and DFSCoerce.

Organisations should review Active Directory credential theft warnings closely, because control of the domain can expose accounts, systems and recovery options across a network.

Target lists and logs did not contain CIS-allocated IP ranges or CIS-country domains, according to the researchers.

Although that pattern alone does not identify a person, the operator’s own notes, custom tool documentation and AI planning sessions were written in Russian, reinforcing CloudSEK’s assessment.

Encryption and Defence Steps

Aurora’s Windows and Linux or ESXi lockers were built from one Zig codebase, an uncommon choice for ransomware.

The Windows sample was named sap.exe, while the Linux and ESXi build was encrypt.out. Both were downloaded from a public Cloudflare R2 bucket and copied to staging hosts via scp.

On Windows, the malware attempts to remove volume shadow copies, resize shadow storage and disable System Restore before encrypting files.

The ESXi mode kills running virtual machines and encrypts virtual-machine files, making ESXi ransomware attack risks especially disruptive because it can affect several business systems. The recovered negotiation data also showed that at least one victim settled a ransom demand.

CloudSEK and TRM Labs traced the payment and identified two confirmed victim payments plus two further payments consistent with separate victims, which moved through shared laundering infrastructure before reaching cash-out.

Defenders should disable LLMNR and NBT-NS, use SMB signing and Extended Protection for Authentication, restrict WinRM to approved administrative hosts, and remove SMBv1 where it remains.

They should examine certificate templates for risky settings and log certificate requests and issuances to catch abuse early.

Teams should rotate the krbtgt password twice, with full replication between resets, after a suspected domain compromise.

They should protect browser-stored credentials, use separate credentials and network segments for backups, and isolate or retire older systems.

Securing virtualisation management interfaces, as stressed in ransomware platform targeting ESXi, can limit the impact of an encryption event.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Onion addressijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onionAurora Tor negotiation site
SHA-256eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207sap.exe Windows locker
SHA-256a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfeencrypt.out Linux and ESXi locker
Filename!!!README!!!DO_NOT_DELETE.txtAurora ransom note
IPv4172.86.113.245Operator VPS
IPv4172.86.90.75Operator VPS
IPv4144.172.116.150Operator VPS
IPv4104.194.134.167Operator VPS used as SOCKS relay
IPv489.106.83.49Rented SOCKS pivot
IPv423.234.108.48Rented SOCKS pivot
IPv4:Port167.88.167.37:50167C2 egress check
IPv4:Port45.61.148.166:21056Rented SOCKS pivot

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago