Cursor Agent used in Aurora intrusions
Ransomware operators used Cursor Agent to execute commands inside victim networks.
- Reported date
- Aug 27, 2026
- Target
- Ten targeted organizations
- Agent type
- Coding agent
- Agent role
- Used by the attacker
The exact incident date was not established. This entry is dated by its source report.
Gambit Security reported that an Aurora ransomware operator used Cursor Agent, running Claude Sonnet, for exploitation inside ten targeted organizations. The investigation examined agent sessions between April 8 and May 21, 2026. August 27 is the report date, rather than a single intrusion date for those victims.
What happened
The operator supplied credentials or an existing route into each environment, then gave the agent objectives and instructions. The agent executed commands, inspected results, and revised unsuccessful attempts. Observed work included internal reconnaissance, privilege assessment, and attempts to exploit authentication infrastructure. Some objectives succeeded; others failed.
This establishes operational agent execution after access had already been obtained. It does not establish that the agent independently performed initial compromise or deployed ransomware. Gambit separately observed manual distribution of an Aurora encryptor within a victim environment. The report also describes another activity cluster, attributed with medium confidence, which is not counted as an additional agentic incident here.
Evidence in the reporting
- Incident evidence
- Some eventually succeeded in achieving the objective
- Agent involvement
- the agent was given credentials or an existing route