Russian hackers unleashed Cursor AI agent to infiltrate nearly a dozen corporate networks
The newish Aur0ra ransomware gang repeatedly bypassed AI safeguards by claiming its attacks were authorized simulations.

Cursor is an AI coding agent that can run on mutiple platforms. Image by bella1105 | Shuterstock
- Aur0ra targeted at least 10 corporate networks using Cursor AI to support hands-on exploitation.
- Researchers saw attackers use Cursor for network scanning, credential attacks, and other intrusion tasks.
- The hackers bypassed some AI safeguards by claiming the attacks were only tests or simulations.
- Gambit estimates AI assistance made the attackers 30% to 50% faster during intrusions.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
New research exposes the inner workings of Aur0ra – a Russian-speaking hacker group that has been using SpaceX’s Cursor AI to carry out cyberattacks targeting at least 10 corporate networks this past spring.
First emerging in April, the relatively new Russian-speaking gang was found to have used a Cursor Agent running on Claude Sonnet 4.5 “to assist with hands-on exploitation” once inside the target networks.
According to new research from Gambit Security published Thursday, the attacks took place between April 8th and May 21st of this year.
Cursor – the AI-powered coding agent officially acquired by Musk’s SpaceX on August 14th – is primarily used by developers to help write, edit, and manage software.
The autonomous AI agent can be run on multiple major models – including Claude, GPT, Gemini, and Grok – making the findings much more significant as talk of AI-fueled cyberattacks permeates the industry.
Cursor AI unleashed inside corporate networks
Gambit said it was able to view 28 exposed chat sessions among other Aur0ra infrastructure giving them inside access to how the AI agent was used during a real-world cyberattack.
Targeting organizations across multiple countries, Gambit researchers observed two separate attack chains – one involving a Linux ransomware variant capable of targeting ESXi environments, and the second using attacker-controlled S3-compatible infrastructure to exfiltrate data.
In the first instance, the hackers were said to have deployed a Linux variant of its signature Aur0ra ransomware, dubbed ESXi ransomware, designed to encrypt VMware ESXi environments.
Using Cursor with Claude Sonnet 4.5 in thinking mode, Gambit said the hackers would first give the AI coding agent a set of credentials or a way into the victim organization, before assigning it “standard exploitation tasks.”
Tasks included internal network scanning, privilege enumeration, credential attacks, NTLM relay attempts, and certificate-based attacks.
Hackers trick AI by calling attacks “simulations”
In some tasks, Aur0ra told the agent which tools or techniques to use, in others the agent would be given a sole objective – and free rein on how to accomplish it.
This is where it got interesting. Gambit said that when commands failed, Cursor repeatedly modified them or suggested alternative approaches based on the victim environment.
At times, the agent even gave the attackers a numbered list of possible next steps, allowing the attackers to simply choose a number to carry out the next step.
The hackers also placed explicit restrictions on the AI, repeatedly instructing Cursor not to perform DCSync attacks, lock user credentials, or create new computer objects within the compromised domains, Gambit said.
The researchers noted that Cursor had refused some of the requests, identifying them as potentially malicious or illegal. But according to Eyal Sela, Gambit’s Director of Threat Intelligence, those safeguards proved relatively easy to circumvent.
Sela told Reuters the hackers “would almost always circumvent the refusals by restarting the dialogue and emphasizing that the hack was all part of a test.”
AI makes ransomware attacks faster
Max Gannon, Cyber Intelligence Team Manager at Cofense, told Cybernews that what stands out the most is how simple the workaround for Cursor was.
The threat actors did not need to use advanced techniques to bypass the AI guardrails, he explained.
They [Aur0ra] just told it the hack was a test, and the agent talked itself into believing that framing, even saying to itself that a test environment made the activity legal,said Max Gannon, Cyber Intelligence Team Manager at Cofense.
Gannon says it is a “reminder that guardrails built to catch malicious keywords or requests can still be defeated by a convincing cover story."
Meanwhile, Sela estimated the AI assistance made the attackers roughly “30% to 50% faster,” allowing the hackers to skip some of the manual work traditionally required during an intrusion.
Second Aur0ra cluster targets eight organizations
In the second cluster, researchers observed what appeared to be a different Aur0ra operator moving laterally through victim environments before exfiltrating data to self-hosted S3-compatible storage.
That cluster was linked with medium confidence to Aur0ra and targeted eight organizations across Israel, Germany, Austria, Spain, the US, and Argentina.
At least some of the organizations targeted during the campaign were successfully breached.
Reuters independently identified several victims, including Belgian cleaning-products manufacturer Christeyns, German garage-door manufacturer Teckentrup, Scotland-based Helideck Certification Agency, and Louisiana title insurance company Bayou Title.
Bayou Title also appeared on Aur0ra’s dark web leak site along with 8 file samples. The leak site currently lists 31 victims.
Overall, victims ranged from smaller manufacturers and professional-services firms to major international companies, including Sumitomo Electric Bordnetze, Corporación Primax, and ALS Global.
Gambit cautioned that the full extent of Cursor’s role in each intrusion remains unclear.
Notably, Cursor was originally developed by the AI start-up Anysphere, before it was sold to SpaceX. The attacks themselves occurred before the acquisition.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.