-
An Aurora ransomware operator used Cursor’s AI agent during attacks on at least seven companies.
-
The hacker often claimed the work was a security test after the AI refused harmful requests.
-
Researchers say the case shows how AI agents can make cyberattacks faster and easier.
Russian-speaking hackers used Cursor, an AI tool from SpaceX, to help attack at least seven companies this year.
Gambit Security found chat logs from an Aurora ransomware hacker. The logs covered April 8 to May 21 and showed the hacker using Cursor inside victim networks. The case shows how a false test claim can weaken AI safety checks.
How the Hackers Used Cursor
Gambit found the activity on an Aurora server that the group left open online. The server held tools, command records, stolen credentials, and Cursor chat logs.
The chats show the hacker asking Cursor to find passwords, check user rights, and help reach other systems. The agent also helped with network scans and other attack steps. The hacker sometimes told Cursor that the work was part of an approved test. When the agent refused a request, the hacker could start a new chat and repeat that claim.
Gambit said the agent then carried out many actions for the attacker. Some tasks worked, while others failed and led to new attempts. Cursor acted more like a hands-on helper than a simple chatbot. The hacker could give it a goal or follow its suggestions.
Gambit saw Cursor help across ten target organizations. Reuters reported that at least seven companies suffered attacks with Cursor’s help. CloudSEK separately found evidence of attacks against more than 20 organizations, though it did not say that Cursor helped in every case.
The Victims were Spread Across Several Countries
Reuters identified six of the companies from the chat records. They included Belgian cleaning products maker Christeyns, German garage door maker Teckentrup and Scotland’s Helideck Certification Agency.
The other three were an Argentine drug supplier, an Italian manufacturer and Louisiana-based Bayou Title. Reuters said none of the six companies answered its requests. Bayou Title also appeared on Aurora’s leak site.
On the other hand, CloudSEK found a wider campaign. It said the hacker attacked more than 20 organizations across nine countries between April and July. The group gained deep or live access at 17 of them. Four later appeared on Aurora’s leak site.
AI Helped Speed up the Work
Eyal Sela, Gambit’s director of threat intelligence, said Cursor likely made the hacker 30% to 50% faster. The agent handled routine work and helped solve problems. That saved the hacker time between attack steps.
The sessions Gambit reviewed used Claude Sonnet 4.5. Anthropic makes the Claude models that power many AI tools, including coding agents. Gambit said Cursor refused some harmful requests. Yet the hacker could often get around those refusals by claiming the work was legal.
That matters because AI agents can run commands, inspect files and use other software. A criminal can turn an AI suggestion into a real action. Gambit’s records show that most commands did not work on the first try. The hacker and the AI then changed scripts or commands until some tasks worked.
Regulators are also examining how tech platforms handle safety. Ofcom’s investigation into Telegram is part of a broader crackdown on online harm under the UK’s Online Safety Act, which can result in fines of up to £18 million or 10% of global revenue for non-compliance. The probe follows evidence from the Canadian Centre for Child Protection suggesting CSAM is being shared on the platform.
Aurora did not Rely on AI Alone
The ransomware gang also used standard hacking tools. Gambit found tools for network scanning, password theft and access inside Windows networks. The hacker also used public exploit code and custom scripts.
The group used a Linux version of Aurora ransomware against VMware ESXi systems. Gambit found that the malware could stop running virtual machines and then encrypt their files.
CloudSEK found two Aurora ransomware types for Windows and Linux. Both used Zig, a coding language that few ransomware gangs use. CloudSEK also found shell history, credential data, Cursor chats, and ransomware files on the server. The data showed the campaign from break-in to data theft and ransom activity.
What this Means for AI Security
The case shows why AI safety rules are hard to enforce. An AI model can refuse a harmful request. But the user can change the story and ask again. If the agent trusts that story, the same safety rule may no longer stop the action.
The risk grows when an AI agent can reach real systems. A chatbot that only gives advice has limited reach. An agent that can use tools can help carry out the work. Criminals also do not need a fully autonomous AI hacker. They can use AI as a fast helper while making key decisions themselves.
Cursor joined SpaceX in August after SpaceX completed its deal for Anysphere, the company behind Cursor. SpaceX valued the deal at about $60 billion in filings. The attacks took place before the deal closed. For now, Cursor, SpaceX and Anthropic haven’t commented on the discovery.
For defenders, the message is simple. AI-assisted hacking is not a potential threat anymore; it’s already here. Hackers are now using AI technologies during their hacks right now.