Russian-speaking hackers used AI assistant for cyberattacks on companies
A Russian-speaking operator of the Aurora group, which engages in attacks using ransomware, used the AI assistant Cursor for planning and conducting cyberattacks on corporate networks. CloudSEK researchers tracked attacks on more than 20 organizations in nine countries, and Gambit Security separately recorded the use of Cursor during operations against ten targets.
This is stated in two independent investigations by cybersecurity companies Gambit Security and CloudSEK, published on August 27.
Gambit Security discovered open infrastructure associated with Aurora, which allowed researchers to see part of the group's operations inside the networks of potential victims. According to their data, from April 8 to May 21, 2026, the operator used Cursor Agent with the Claude Sonnet model during attacks on ten organizations.
The AI was given existing access to the network or credentials, after which it was tasked with performing individual stages of the attack. In particular, the agent was used to research internal networks, check user rights, find ways to expand access, and form commands and scripts for further actions.
In some cases, the operator gave Cursor only the final goal, and the AI itself proposed possible next steps. In other cases, the hacker defined a specific approach or asked to continue a previously drawn-up attack plan. Researchers note that many of the AI's first attempts were unsuccessful, after which the agent adjusted commands and scripts depending on the results obtained.
CloudSEK independently investigated the infrastructure of one of the Aurora operators and obtained data on a much broader campaign. According to the company's estimate, from April to July 2026, he attacked more than 20 organizations in nine countries. In at least 17 cases, the attacker managed to obtain interactive access or domain-level access, and four victims subsequently appeared on the Aurora leak site.
CloudSEK considers the operator to be Russian-speaking with a high degree of confidence. Researchers noted that the materials, documentation, session notes, and plans he created in Cursor were written in Russian. In addition, for several months there were no IP ranges or domains of CIS countries in the target lists.
The obtained data also indicates that the use of AI was not limited to writing malicious code. Cursor actually became a tool to support the operator during various stages of penetrating corporate networks - from planning actions to preparing and adjusting technical commands.
The Aurora group itself, according to researchers, has been active since at least April 2026. It uses ransomware to encrypt corporate data and has its own site for publishing information about victims who refuse to comply with the attackers' demands.
Based on materials from: Gambit Security, CloudSEK