Detect Deepfakesby Resemble AI
Agentic AI attack

Cursor Agent used in Aurora intrusions

Ransomware operators used Cursor Agent to execute commands inside victim networks.

Reported date
Aug 27, 2026
Target
Ten targeted organizations
Agent type
Coding agent
Agent role
Used by the attacker

The exact incident date was not established. This entry is dated by its source report.

Updated Sep 23, 2026 · 1 min read

Gambit Security reported that an Aurora ransomware operator used Cursor Agent, running Claude Sonnet, for exploitation inside ten targeted organizations. The investigation examined agent sessions between April 8 and May 21, 2026. August 27 is the report date, rather than a single intrusion date for those victims.

What happened

The operator supplied credentials or an existing route into each environment, then gave the agent objectives and instructions. The agent executed commands, inspected results, and revised unsuccessful attempts. Observed work included internal reconnaissance, privilege assessment, and attempts to exploit authentication infrastructure. Some objectives succeeded; others failed.

This establishes operational agent execution after access had already been obtained. It does not establish that the agent independently performed initial compromise or deployed ransomware. Gambit separately observed manual distribution of an Aurora encryptor within a victim environment. The report also describes another activity cluster, attributed with medium confidence, which is not counted as an additional agentic incident here.

Evidence in the reporting

Incident evidence
Some eventually succeeded in achieving the objective
Agent involvement
the agent was given credentials or an existing route

Sources