Independent reporting on American politics
STATE BEACON

Aurora ransomware gangs weaponise SpaceX’s Cursor AI in multi‑country attacks

Security researchers have documented that Aurora ransomware operators used SpaceX’s Cursor AI coding assistant in at least ten attacks across nine countries between April and July 2026, automating steps such as NTLM‑relay, AD CS abuse and credential harvesting.

By State Beacon·
SpaceX headquarters building at 1 Rocket Road, Hawthorne, California – the development site of the Cursor AI coding assistant

Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from security firms CloudSEK and Gambit Security. The documented activity covers at least ten distinct attacks across nine countries between April 8 and May 21 2026, with a broader leak indicating activity against more than 20 organisations during the April‑July window.

Security‑firm analysis confirms AI‑enabled tooling

The Hacker News article published on 31 August 2026 cites two independent investigations. CloudSEK uncovered an open‑directory leak that spanned "months of activity" targeting over 20 organisations in nine countries. Gambit Security corroborated the leak and added that the Aurora operators used Cursor to run Anthropic's Claude Sonnet model, effectively turning the coding assistant into a hands‑on exploitation aid.

Both firms traced the use of Cursor back to shell‑history artifacts and encryptor scripts that referenced the tool by name. CloudSEK’s report notes that four of the victims have been listed on its public data‑leak site, though the companies’ names remain undisclosed in the public summary.

Scope and geography of the campaign

The combined evidence points to ten distinct targets that employed Cursor during the April‑July 2026 period. Those targets were spread across nine countries, though the specific nations were not enumerated in the source excerpts. The broader leak mentions organisations ranging from an Argentine pharmaceutical distributor to an Italian manufacturer, as reported by Reuters and quoted in the Hacker News piece.

In total, more than 20 organisations fell victim to the broader Aurora activity, suggesting that the ten Cursor‑assisted attacks represent a significant subset of a larger ransomware campaign.

How Cursor was weaponised

According to the Gambit Security analysis, the Aurora operators used Cursor to plan attacks in Russian while explicitly excluding CIS‑range IPs and domains. The AI assistant generated code snippets that automated several exploitation steps:

  • NTLM‑relay attacks using tools such as PetitPotam, Coerce Plus and PrinterBug, with Impacket's ntlmrelayx to forward authentication.
  • Active Directory Certificate Services (AD CS) abuse, enabling the creation of fraudulent certificates for lateral movement.
  • Credential harvesting, where the AI‑generated scripts extracted stored credentials from compromised hosts.

These steps illustrate a shift from manual scripting to AI‑augmented automation, reducing the time required to move from initial access to privileged escalation.

SpaceX background and the broader AI‑risk context

SpaceX, founded on 14 March 2002, is headquartered in Hawthorne, United States, and is led by chief executive Elon Musk. Public data lists the company as employing roughly 160 people, though the packet notes that Wikidata figures may lag behind current headcounts. Cursor is marketed as a commercial coding assistant that runs on large‑language‑model back‑ends, including Anthropic's Claude series.

The emergence of Cursor in ransomware operations arrives as U.S. regulators debate safeguards for autonomous AI agents that could be misused. The documented use of a commercial AI tool in real‑world ransomware attacks provides a concrete example of the threat landscape that policymakers are seeking to address.

What remains unknown

The security firms have not disclosed the full list of affected organisations, nor have they quantified the financial impact of the attacks. Details on whether the victims reported data exfiltration, ransom payments, or system downtime are absent from the current reports. Additionally, the exact mechanism by which the Aurora operators obtained access to Cursor’s API keys or subscription credentials has not been revealed.

Further investigation by CloudSEK, Gambit Security, or other threat‑intel groups will be needed to map the full extent of AI‑enabled ransomware activity and to determine whether other criminal groups have adopted similar tactics.

Key metrics of Cursor‑assisted Aurora attacks (April–July 2026)

Key metrics of Cursor‑assisted Aurora attacks (April–July 2026)
MetricValue
Number of distinct targets using Cursor10
Countries affected9

Source: The Hacker News (citing CloudSEK & Gambit Security).

As regulators grapple with AI‑misuse safeguards, the Aurora‑Cursor case underscores how commercial AI tools can be repurposed for sophisticated cyber‑crime. Organizations are urged to monitor AI‑related threat vectors and to consider additional controls around the use of external coding assistants in sensitive environments.