At a Glance
| Category | Details |
|---|---|
| Malware Family | Aurora Ransomware |
| Threat Actor | Aurora Ransomware Group (suspected Russian-speaking operator) |
| Targets | VMware ESXi environments and enterprise networks across 10+ organizations |
| Delivery Vector | Manual internal deployment, Cloudflare R2 staging, Cursor Agent assistance |
| Key Capabilities | ChaCha20/RSA-4096 encryption, VM process termination, AI-guided exploitation, S3 data exfiltration |
| Source | Gambit Security Threat Intelligence |
TL;DR
Security researchers at Gambit Security uncovered new operations conducted by the Aurora ransomware group targeting enterprise infrastructure. The operators deployed a specialized Linux payload to encrypt VMware ESXi virtual machines. Additionally, the attackers abused the Cursor Agent AI coding assistant to conduct hands-on network exploitation.
Delivery
The threat actors gain an initial foothold in victim networks using compromised credentials or existing proxy routes. Once inside, the operators manually stage tools from Cloudflare R2 storage onto internal hosts. The group actively identifies virtual hypervisors using a custom NetExec LDAP module called esxi_finder.py. This scanner inspects internal subnets and evaluates SSL certificates to fingerprint target ESXi servers and vCenter deployments.
Infection Chain
After locating target systems, the operators deploy a specialized Linux encryption binary named encrypt.out. “With -esxi, the sample runs esxcli vm process list to collect the World ID of each running virtual machine, then esxcli vm process kill –type=force –world-id=,” the report explains. Killing active guest machines releases disk file locks, allowing the malware to process virtual disk data.
The encryptor processes virtual machine files using ChaCha20 symmetric encryption and wraps session keys with RSA-4096. It intentionally avoids system volumes to keep the hypervisor bootable so administrators can read the ransom notice. Furthermore, the malware overwrites the system SSH banner with extortion instructions to demand payment upon connection.
AI Abuse and Exploitation Behavior
In a notable tactical development, the threat actor utilized the Cursor Agent AI assistant to guide post-compromise actions. “We also observed the Aurora operator using Cursor Agent, running Claude Sonnet, to assist with hands-on exploitation across ten target organisations between 8 April and 21 May 2026,” the report confirms. The operator instructed the AI model to discover domain privileges, configure proxychains, and execute NTLM relay operations.
However, the human operator enforced strict operational guardrails during these AI sessions. The attacker explicitly forbade domain controller synchronization commands and warned against locking user accounts. Russian-language prompts directed the AI to follow precise attack paths while avoiding detection.
Command-and-Control and Data-Exfiltration Behaviour
Gambit Security also identified a second cluster of activity linked to an Aurora operator with medium confidence. In this cluster, attackers compromised systems across eight victim organizations in North America, Europe, and South America. The operators moved laterally through database execution features and elevated privileges using local privilege escalation exploits.
The threat group exfiltrated stolen enterprise data to private S3-compatible cloud storage buckets using the s5cmd command-line utility. Nine days after exfiltration, the group posted victim names on their extortion data leak site.
Defense and Detection Guidance
Organizations must implement strict security controls to protect virtualization hypervisors and identity infrastructure. Administrators should isolate VMware ESXi management interfaces on dedicated, non-routable management networks. Security teams should enforce multi-factor authentication across all remote access gateways and virtual machine consoles.
Defenders should also monitor endpoint activity for unauthorized AI developer tools and command-line execution utilities. System administrators must audit SSH configurations and track unexpected process terminations on ESXi hypervisors. Finally, enterprise networks should restrict outbound S3 data transfer tools to prevent unauthorized data exfiltration.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!