// news

Aurora Ransomware Used the Cursor AI Agent to Plan AD Attacks — Both Lessons

On 27 August 2026, CloudSEK published “The Aurora Files”: an exposed affiliate server from the Aurora ransomware operation leaked the operator’s tooling, command history, stolen credentials, the encryptor build — and, most striking, chat logs with the AI coding assistant Cursor. A Russian-speaking affiliate used the agentic assistant to plan intrusions and Active Directory escalation, reasoning in Russian throughout.

Scale: 20+ organizations across nine countries from April to July 2026, domain-level or interactive access at 17, four named on Aurora’s leak site. Manufacturing, food, agriculture and professional services were hit. In one of the busiest engagements the assistant worked through an Active Directory Certificate Services (AD CS) exploitation plan — the ESC chains that turn a weak certificate template into a path to Domain Admin.

Lesson 1: AI collapsed the attacker skill floor

A competent AD CS attack used to require an experienced operator. Now the assistant drafts and reasons through the chain step by step — faster, cleaner, with fewer mistakes. The defensive takeaway: assume even a mid-tier intruder now operates like a strong specialist, and your reaction window is shrinking. Fundamentals matter more than ever:

  • Audit AD CS for ESC1–ESC8. Templates that allow requester-supplied SAN, HTTP web-enrollment, NTLM relay to the CA, over-broad enrollment rights — the classic holes an assistant finds first.
  • Credential hygiene and tiering. Tier 0/1/2 separation, no Domain Admins on workstations, LAPS — this breaks the path from first host to domain controller.
  • Monitor certificate issuance and Kerberos anomalies to catch ESC abuse in the act, not in the aftermath.

Lesson 2: the same agent is now your risk too

The flip side: your own developers run the same agentic assistants (Cursor, Claude Code) with your privileges — access to repos, keys, production. The agent reads files, reaches the network, and calls dozens of unvetted MCP servers. Prompt injection and tool poisoning turn a helpful assistant into an insider. Attackers have already normalized agents as a weapon; it’s time to normalize control over your own.

That’s why we built Airlock — a runtime firewall that sits between the agent and the system and gates every action (instead of trusting the prose inside a skill). For the deeper threat picture, see our writeup on what an AI coding agent can do on your machine.

What to do

Aurora is a reminder that both offense and defense are moving into the agentic world. For perimeter and domain, external network penetration testing and targeted Active Directory penetration testing (including AD CS/ESC) find the weak link; an assumed-breach assessment shows the real path from a foothold to domain compromise; and agentic-AI threat modeling governs the assistants your own team runs. Get in touch and we’ll find that weak chain before someone else does.

Related service: ransomware readiness assessment — attack-path simulation, backup isolation and detection validation against real ransomware TTPs.

Source: CloudSEK, “Caught in 4K: The Aurora Files” (27 August 2026); additional reporting by CybersecurityNews, GBHackers, OODAloop.

// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement