AI

An Exposed Server Revealed How a Ransomware Affiliate Used AI to Plan Attacks

A CloudSEK investigation, with on-chain analysis from TRM Labs, examined a misconfigured server belonging to an affiliate of the Aurora ransomware operation. The exposed directory tied the operator to more than 20 organisations across nine countries, showed the attacker using the AI coding assistant Cursor to plan intrusions, and let researchers follow ransom payments into cryptocurrency laundering infrastructure.

[For more news, click here]

Ransomware researchers usually meet their subjects late. By the time an investigation opens, the intrusion is finished, the files are encrypted, and the work becomes reconstruction, a careful backward read through a victim's ruined network to infer what the intruder did and how. A CloudSEK investigation ran that sequence in reverse and its researchers found themselves studying an operation from the inside, through the attacker's own machine.

An affiliate of the Aurora ransomware group left a server exposed, and inside sat the operator's Linux home directory, shell history, credential material, attack tooling, stolen victim data, planning notes, and the Aurora encryptor itself. It was, in effect, the working environment of a professional extortionist, laid open for anyone who happened upon it.

The Scale of the Operation

The dataset covered activity between April and July 2026 during which time the operator compromised more than 20 organisations across nine countries, reaching domain-level or interactive access at 17 of them. Four of those later surfaced on Aurora's public leak site, connecting the private activity inside the server to public extortion. The victims spanned manufacturing and industrial firms, food and agriculture, professional and financial services, transport and logistics, consumer goods, environmental services, and IT and backup infrastructure. The United States accounted for the largest share of confirmed victims.

In several cases the operator got access to an entire network, including domain administrator credentials, Kerberos tickets, VPN logins, Group Policy information, and backup-system credentials. Most of the affected organisations never appeared on a public leak site, which means the reach was quieter and wider than the group's visible victim count suggests. CloudSEK said it began coordinated notification through national CERTs and affected organisations for victims who had not already been identified.

AI as an Operational Tool, Not Just a Code Generator

The finding likely to unsettle business and security leaders most is Cursor, a mainstream AI coding assistant that legitimate developers use every day. Recovered sessions showed the operator conversing with Cursor in Russian to reason through attack sequences, including detailed planning around Active Directory Certificate Services exploitation. The chat history reflected sustained back-and-forth with the tool during live victim engagements, the contents of which shift to the familiar worry about AI and cybercrime.

Much of the public conversation has fixated on AI writing malware or drafting phishing emails. In this case, the assistant worked as a planning partner, helping an attacker think through how to move across an enterprise environment. Readily available tools are being folded into criminal workflows in the same way they are folded into ordinary engineering work. A kind of portability making them useful to both sides.

A Repeatable Playbook

Since the whole environment was exposed, CloudSEK could rebuild a method the operator reused across targets. The attacker repeatedly ran Active Directory and SMB discovery, pulled password policies, and performed Kerberoasting and AS-REP Roasting. For privilege escalation the approach adapted to each network, drawing on a custom noPac chain, Active Directory Certificate Services abuse across ESC1, ESC6, and ESC8, and NTLM relay attacks using PetitPotam, PrinterBug, and DFSCoerce.

Exploit code for at least a dozen vulnerabilities was stored in the environment, much of it public proof-of-concept material, though some had been modified and a FortiOS toolkit had been rebuilt as a standalone framework. The operator also kept custom NetExec modules, including tools to harvest browser credentials across several browsers and to identify ESXi infrastructure. On that evidence, CloudSEK assessed with high confidence that the individual was operating as a full Aurora affiliate rather than an initial-access broker, since the activity carried well past gaining a foothold into credential theft, domain compromise, exfiltration, ransomware staging, and extortion.

Ransomware Written in an Unusual Language

The server held multiple versions of the Aurora encryptor for Windows and for Linux and ESXi systems, both written in Zig, a language rarely seen in ransomware development. The two builds appear to share a single codebase compiled for different operating systems, and the encryptor offers options to speed up or customise its work, including partial-file encryption, multithreading, and file-size restrictions.

The Linux and ESXi variant was built with virtual infrastructure where before encryption begins, it enumerates running virtual machines and force-terminates them, and rather than dropping a ransom note as a file, it can rewrite the ESXi host's SSH login banner so the demand greets any administrator who connects to the server. CloudSEK's full report includes indicators of compromise and a detection rule aimed at spotting the behaviour.

Following the Money

The exposed files opened a window onto the finances as well as the wallet address the operator listed for payment held 7 BTC at the time of analysis, a balance CloudSEK read as accumulated proceeds from several victims rather than a single payout, and itself a strong sign that the operation generates real revenue. A key recovered from the encryptor gave researchers access to records from a completed negotiation, though the victim involved is not being named.

Working with TRM Labs, CloudSEK traced the resulting payment on-chain and followed how the funds moved afterward. The wider analysis identified two confirmed victim payments and two more consistent with separate victims. Each began on its own path before several converged at shared consolidation points on the way toward cash-out infrastructure. Researchers noted differing splits across the payments they examined, including 35/65, 21/79, 46/54, and 40/60, with no single ratio repeating, which suggests the division of proceeds between participants was not a fixed percentage. Most of the traced funds passed through two dominant consolidation clusters, while one payment followed a peeling chain, drifting across a sequence of smaller transactions instead of the main hubs. The pattern hints that Aurora-linked activity reaches beyond the victims visible on public leak sites.

Why the View from the Other Side Matters

CloudSEK assessed with high confidence that the operator is Russian-speaking, an assessment grounded in material the attacker created directly, including the Cursor conversations, module documentation, and session notes. Across three months of the operator's target lists, scans, and success logs, no CIS-allocated IP ranges or CIS-country domains appeared. The company was careful to note that this speaks to the operator's language and observed targeting, and does not establish the individual's nationality or physical location.

Most ransomware investigations are exercises in inference, assembled from a victim's damaged systems after the fact. This one let researchers watch the operator's own environment, following how organisations were enumerated, how privilege escalation was attempted, what credentials and tools were stockpiled, how AI shaped the planning, how the ransomware itself worked, and where the money went once it was paid. The result is an unusually complete picture of a modern ransomware affiliate's lifecycle, from the first intrusion to the laundering of the payout. The same tools reshaping legitimate technical work are also reshaping the criminal version of it.

Related Articles

GISEC Global 2026 Opens in Dubai with a Cyber First Agenda and a New Quantum Security Focus

Why Fortinet Is Turning to Intel to Build Its Next Cybersecurity Chip

KnowBe4 and AWS Sign Multiyear Deal to Secure the Workforce of Humans and AI Agents

AI

An Exposed Server Revealed How a Ransomware Affiliate Used AI to Plan Attacks

A CloudSEK investigation, with on-chain analysis from TRM Labs, examined a misconfigured server belonging to an affiliate of the Aurora ransomware operation. The exposed directory tied the operator to more than 20 organisations across nine countries, showed the attacker using the AI coding assistant Cursor to plan intrusions, and let researchers follow ransom payments into cryptocurrency laundering infrastructure.

[For more news, click here]

Ransomware researchers usually meet their subjects late. By the time an investigation opens, the intrusion is finished, the files are encrypted, and the work becomes reconstruction, a careful backward read through a victim's ruined network to infer what the intruder did and how. A CloudSEK investigation ran that sequence in reverse and its researchers found themselves studying an operation from the inside, through the attacker's own machine.

An affiliate of the Aurora ransomware group left a server exposed, and inside sat the operator's Linux home directory, shell history, credential material, attack tooling, stolen victim data, planning notes, and the Aurora encryptor itself. It was, in effect, the working environment of a professional extortionist, laid open for anyone who happened upon it.

The Scale of the Operation

The dataset covered activity between April and July 2026 during which time the operator compromised more than 20 organisations across nine countries, reaching domain-level or interactive access at 17 of them. Four of those later surfaced on Aurora's public leak site, connecting the private activity inside the server to public extortion. The victims spanned manufacturing and industrial firms, food and agriculture, professional and financial services, transport and logistics, consumer goods, environmental services, and IT and backup infrastructure. The United States accounted for the largest share of confirmed victims.

In several cases the operator got access to an entire network, including domain administrator credentials, Kerberos tickets, VPN logins, Group Policy information, and backup-system credentials. Most of the affected organisations never appeared on a public leak site, which means the reach was quieter and wider than the group's visible victim count suggests. CloudSEK said it began coordinated notification through national CERTs and affected organisations for victims who had not already been identified.

AI as an Operational Tool, Not Just a Code Generator

The finding likely to unsettle business and security leaders most is Cursor, a mainstream AI coding assistant that legitimate developers use every day. Recovered sessions showed the operator conversing with Cursor in Russian to reason through attack sequences, including detailed planning around Active Directory Certificate Services exploitation. The chat history reflected sustained back-and-forth with the tool during live victim engagements, the contents of which shift to the familiar worry about AI and cybercrime.

Much of the public conversation has fixated on AI writing malware or drafting phishing emails. In this case, the assistant worked as a planning partner, helping an attacker think through how to move across an enterprise environment. Readily available tools are being folded into criminal workflows in the same way they are folded into ordinary engineering work. A kind of portability making them useful to both sides.

A Repeatable Playbook

Since the whole environment was exposed, CloudSEK could rebuild a method the operator reused across targets. The attacker repeatedly ran Active Directory and SMB discovery, pulled password policies, and performed Kerberoasting and AS-REP Roasting. For privilege escalation the approach adapted to each network, drawing on a custom noPac chain, Active Directory Certificate Services abuse across ESC1, ESC6, and ESC8, and NTLM relay attacks using PetitPotam, PrinterBug, and DFSCoerce.

Exploit code for at least a dozen vulnerabilities was stored in the environment, much of it public proof-of-concept material, though some had been modified and a FortiOS toolkit had been rebuilt as a standalone framework. The operator also kept custom NetExec modules, including tools to harvest browser credentials across several browsers and to identify ESXi infrastructure. On that evidence, CloudSEK assessed with high confidence that the individual was operating as a full Aurora affiliate rather than an initial-access broker, since the activity carried well past gaining a foothold into credential theft, domain compromise, exfiltration, ransomware staging, and extortion.

Ransomware Written in an Unusual Language

The server held multiple versions of the Aurora encryptor for Windows and for Linux and ESXi systems, both written in Zig, a language rarely seen in ransomware development. The two builds appear to share a single codebase compiled for different operating systems, and the encryptor offers options to speed up or customise its work, including partial-file encryption, multithreading, and file-size restrictions.

The Linux and ESXi variant was built with virtual infrastructure where before encryption begins, it enumerates running virtual machines and force-terminates them, and rather than dropping a ransom note as a file, it can rewrite the ESXi host's SSH login banner so the demand greets any administrator who connects to the server. CloudSEK's full report includes indicators of compromise and a detection rule aimed at spotting the behaviour.

Following the Money

The exposed files opened a window onto the finances as well as the wallet address the operator listed for payment held 7 BTC at the time of analysis, a balance CloudSEK read as accumulated proceeds from several victims rather than a single payout, and itself a strong sign that the operation generates real revenue. A key recovered from the encryptor gave researchers access to records from a completed negotiation, though the victim involved is not being named.

Working with TRM Labs, CloudSEK traced the resulting payment on-chain and followed how the funds moved afterward. The wider analysis identified two confirmed victim payments and two more consistent with separate victims. Each began on its own path before several converged at shared consolidation points on the way toward cash-out infrastructure. Researchers noted differing splits across the payments they examined, including 35/65, 21/79, 46/54, and 40/60, with no single ratio repeating, which suggests the division of proceeds between participants was not a fixed percentage. Most of the traced funds passed through two dominant consolidation clusters, while one payment followed a peeling chain, drifting across a sequence of smaller transactions instead of the main hubs. The pattern hints that Aurora-linked activity reaches beyond the victims visible on public leak sites.

Why the View from the Other Side Matters

CloudSEK assessed with high confidence that the operator is Russian-speaking, an assessment grounded in material the attacker created directly, including the Cursor conversations, module documentation, and session notes. Across three months of the operator's target lists, scans, and success logs, no CIS-allocated IP ranges or CIS-country domains appeared. The company was careful to note that this speaks to the operator's language and observed targeting, and does not establish the individual's nationality or physical location.

Most ransomware investigations are exercises in inference, assembled from a victim's damaged systems after the fact. This one let researchers watch the operator's own environment, following how organisations were enumerated, how privilege escalation was attempted, what credentials and tools were stockpiled, how AI shaped the planning, how the ransomware itself worked, and where the money went once it was paid. The result is an unusually complete picture of a modern ransomware affiliate's lifecycle, from the first intrusion to the laundering of the payout. The same tools reshaping legitimate technical work are also reshaping the criminal version of it.

Related Articles

GISEC Global 2026 Opens in Dubai with a Cyber First Agenda and a New Quantum Security Focus

Why Fortinet Is Turning to Intel to Build Its Next Cybersecurity Chip

KnowBe4 and AWS Sign Multiyear Deal to Secure the Workforce of Humans and AI Agents

AI

An Exposed Server Revealed How a Ransomware Affiliate Used AI to Plan Attacks

A CloudSEK investigation, with on-chain analysis from TRM Labs, examined a misconfigured server belonging to an affiliate of the Aurora ransomware operation. The exposed directory tied the operator to more than 20 organisations across nine countries, showed the attacker using the AI coding assistant Cursor to plan intrusions, and let researchers follow ransom payments into cryptocurrency laundering infrastructure.

[For more news, click here]

Ransomware researchers usually meet their subjects late. By the time an investigation opens, the intrusion is finished, the files are encrypted, and the work becomes reconstruction, a careful backward read through a victim's ruined network to infer what the intruder did and how. A CloudSEK investigation ran that sequence in reverse and its researchers found themselves studying an operation from the inside, through the attacker's own machine.

An affiliate of the Aurora ransomware group left a server exposed, and inside sat the operator's Linux home directory, shell history, credential material, attack tooling, stolen victim data, planning notes, and the Aurora encryptor itself. It was, in effect, the working environment of a professional extortionist, laid open for anyone who happened upon it.

The Scale of the Operation

The dataset covered activity between April and July 2026 during which time the operator compromised more than 20 organisations across nine countries, reaching domain-level or interactive access at 17 of them. Four of those later surfaced on Aurora's public leak site, connecting the private activity inside the server to public extortion. The victims spanned manufacturing and industrial firms, food and agriculture, professional and financial services, transport and logistics, consumer goods, environmental services, and IT and backup infrastructure. The United States accounted for the largest share of confirmed victims.

In several cases the operator got access to an entire network, including domain administrator credentials, Kerberos tickets, VPN logins, Group Policy information, and backup-system credentials. Most of the affected organisations never appeared on a public leak site, which means the reach was quieter and wider than the group's visible victim count suggests. CloudSEK said it began coordinated notification through national CERTs and affected organisations for victims who had not already been identified.

AI as an Operational Tool, Not Just a Code Generator

The finding likely to unsettle business and security leaders most is Cursor, a mainstream AI coding assistant that legitimate developers use every day. Recovered sessions showed the operator conversing with Cursor in Russian to reason through attack sequences, including detailed planning around Active Directory Certificate Services exploitation. The chat history reflected sustained back-and-forth with the tool during live victim engagements, the contents of which shift to the familiar worry about AI and cybercrime.

Much of the public conversation has fixated on AI writing malware or drafting phishing emails. In this case, the assistant worked as a planning partner, helping an attacker think through how to move across an enterprise environment. Readily available tools are being folded into criminal workflows in the same way they are folded into ordinary engineering work. A kind of portability making them useful to both sides.

A Repeatable Playbook

Since the whole environment was exposed, CloudSEK could rebuild a method the operator reused across targets. The attacker repeatedly ran Active Directory and SMB discovery, pulled password policies, and performed Kerberoasting and AS-REP Roasting. For privilege escalation the approach adapted to each network, drawing on a custom noPac chain, Active Directory Certificate Services abuse across ESC1, ESC6, and ESC8, and NTLM relay attacks using PetitPotam, PrinterBug, and DFSCoerce.

Exploit code for at least a dozen vulnerabilities was stored in the environment, much of it public proof-of-concept material, though some had been modified and a FortiOS toolkit had been rebuilt as a standalone framework. The operator also kept custom NetExec modules, including tools to harvest browser credentials across several browsers and to identify ESXi infrastructure. On that evidence, CloudSEK assessed with high confidence that the individual was operating as a full Aurora affiliate rather than an initial-access broker, since the activity carried well past gaining a foothold into credential theft, domain compromise, exfiltration, ransomware staging, and extortion.

Ransomware Written in an Unusual Language

The server held multiple versions of the Aurora encryptor for Windows and for Linux and ESXi systems, both written in Zig, a language rarely seen in ransomware development. The two builds appear to share a single codebase compiled for different operating systems, and the encryptor offers options to speed up or customise its work, including partial-file encryption, multithreading, and file-size restrictions.

The Linux and ESXi variant was built with virtual infrastructure where before encryption begins, it enumerates running virtual machines and force-terminates them, and rather than dropping a ransom note as a file, it can rewrite the ESXi host's SSH login banner so the demand greets any administrator who connects to the server. CloudSEK's full report includes indicators of compromise and a detection rule aimed at spotting the behaviour.

Following the Money

The exposed files opened a window onto the finances as well as the wallet address the operator listed for payment held 7 BTC at the time of analysis, a balance CloudSEK read as accumulated proceeds from several victims rather than a single payout, and itself a strong sign that the operation generates real revenue. A key recovered from the encryptor gave researchers access to records from a completed negotiation, though the victim involved is not being named.

Working with TRM Labs, CloudSEK traced the resulting payment on-chain and followed how the funds moved afterward. The wider analysis identified two confirmed victim payments and two more consistent with separate victims. Each began on its own path before several converged at shared consolidation points on the way toward cash-out infrastructure. Researchers noted differing splits across the payments they examined, including 35/65, 21/79, 46/54, and 40/60, with no single ratio repeating, which suggests the division of proceeds between participants was not a fixed percentage. Most of the traced funds passed through two dominant consolidation clusters, while one payment followed a peeling chain, drifting across a sequence of smaller transactions instead of the main hubs. The pattern hints that Aurora-linked activity reaches beyond the victims visible on public leak sites.

Why the View from the Other Side Matters

CloudSEK assessed with high confidence that the operator is Russian-speaking, an assessment grounded in material the attacker created directly, including the Cursor conversations, module documentation, and session notes. Across three months of the operator's target lists, scans, and success logs, no CIS-allocated IP ranges or CIS-country domains appeared. The company was careful to note that this speaks to the operator's language and observed targeting, and does not establish the individual's nationality or physical location.

Most ransomware investigations are exercises in inference, assembled from a victim's damaged systems after the fact. This one let researchers watch the operator's own environment, following how organisations were enumerated, how privilege escalation was attempted, what credentials and tools were stockpiled, how AI shaped the planning, how the ransomware itself worked, and where the money went once it was paid. The result is an unusually complete picture of a modern ransomware affiliate's lifecycle, from the first intrusion to the laundering of the payout. The same tools reshaping legitimate technical work are also reshaping the criminal version of it.

Related Articles

GISEC Global 2026 Opens in Dubai with a Cyber First Agenda and a New Quantum Security Focus

Why Fortinet Is Turning to Intel to Build Its Next Cybersecurity Chip

KnowBe4 and AWS Sign Multiyear Deal to Secure the Workforce of Humans and AI Agents

Latest News

Top Stories

Top Stories

Big Tech

Big Tech

Technology

artificial intelligence

artificial intelligence

Finance

Startups

Startups

Technology

Technology

Big Tech

Big Tech

MENA News

MENA News

Media Partnerships