Aurora Ransomware Affiliate Uses Cursor AI to Plan Attacks Against 20+ Organizations
Brief
An exposed open directory has revealed months of activity linked to a Russian-speaking affiliate of the Aurora ransomware operation.
CloudSEK said the operator targeted more than 20 organizations across nine countries between April and July 2026, gaining domain-level or interactive access at 17 victims.
The unprotected Linux home directory was reportedly served through a file listing on port 8888. It contained victim folders, Kerberos tickets, credential dumps, Active Directory data , shell-history files, Cursor AI chat logs, exploit tools, and Aurora ransomware binaries.
Four organizations documented in the files were later listed on Aurora’s public leak site. CloudSEK assessed with high confidence that the actor was an Aurora affiliate conducting intrusions directly, rather than an initial-access broker selling access to other criminals.
