Published on August 27, 2026

Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations


Severity

High

Detail

Researchers have uncovered an Aurora ransomware affiliate that leveraged an AI coding assistant to plan and refine cyberattacks against more than 20 organizations across nine countries between April and July 2026. The activity was exposed through a misconfigured server that provided investigators with visibility into the attacker’s tools, command history, credentials, AI chat records, and ransomware payloads.

According to CloudSEK, the threat actor successfully gained domain-level or interactive access to 17 organizations, while at least four victims were later listed on Aurora’s ransomware leak site. The affected organizations primarily operated in the manufacturing, food, agriculture, and professional services sectors. Evidence suggests the operator acted as a ransomware affiliate conducting intrusions directly rather than an initial access broker selling compromised access.

How?

The attack began when the threat actor accessed victim environments through rented SOCKS proxy infrastructure and conducted reconnaissance using publicly available offensive security tools. Network enumeration was performed using NetExec, while password policy information, credentials, and Active Directory data were collected from compromised systems. The attacker also gathered SAM, LSA, Group Policy, and BloodHound data to map the target environment and identify privilege escalation opportunities.

Privilege escalation was achieved through a combination of ASREPRoasting, Kerberoasting, NTLM relay attacks, and Active Directory Certificate Services (AD CS) abuse. Additional techniques such as PetitPotam, PrinterBug, and DFSCoerce were used to facilitate credential theft and unauthorized access within victim networks.

During the later stages of the campaign, the threat actor used the Cursor AI coding assistant to refine attack plans and evaluate exploitation paths. Recovered chat sessions indicated that AI-assisted guidance was used to analyze reconnaissance results and support decision-making, particularly for AD CS-related attacks.

After obtaining sufficient privileges, Aurora ransomware was deployed across Windows, Linux, and VMware ESXi systems. The malware attempted to disable recovery mechanisms, delete volume shadow copies, and encrypt files and virtual machine assets, increasing operational disruption and reducing recovery options for affected organizations.

Indicator of Compromises (IoCs)

The table below shows a selection of indicators of compromise (IoCs) associated with malicious activity.

TypeIndicatorDescription
Onion Addressijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid[.]onionAurora ransomware negotiation portal
SHA-256eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207sap.exe Windows ransomware payload
SHA-256a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfeencrypt.out Linux/ESXi ransomware payload
Filename!!!README!!!DO_NOT_DELETE[.]txtAurora ransom note
IPv4172[.]86[.]113[.]245Operator VPS infrastructure
IPv4104[.]194[.]134[.]167SOCKS relay infrastructure

Conclusion

This campaign demonstrates how ransomware operators are increasingly incorporating AI-powered tools into their attack workflows to accelerate planning, privilege escalation, and post-compromise activities. While the underlying techniques remain well-known, the use of AI assistants may reduce the time and expertise required to progress through attack stages.

Organizations should strengthen Active Directory security controls, monitor for credential theft activity, review certificate services configurations, disable legacy name resolution protocols such as LLMNR and NBT-NS, enforce SMB signing, and ensure critical systems and backups are adequately segmented from production environments.

Source

https://cybersecuritynews.com/ransomware-hacker-uses-ai/