AI-assisted ransomware campaign · visual reconstruction

What happened: the agent was told it was “only a test”

A ransomware operator used a commercial coding agent as an always-available intrusion assistant. When the agent refused, the operator reframed the work as an authorized simulation and restarted the session. The agent accelerated the operator; Active Directory and AD CS misconfiguration enabled the domain compromises.

Apr 8 – May 21Agent sessions
Apr – Jul 2026Full operator window
28Recovered sessions
10Cursor-assisted targets
20+ / 9Victims / countries
17Domain-level access
4Named on leak site
Threat actor · Aur0ra / Aurora

Russian-speaking ransomware affiliate

A new extortion operation reported active from around April 2026, running a leak site at exposedrecords[.]io. CloudSEK assessed the exposed operator as a direct Aurora affiliate rather than an initial-access broker: the same directory holds the recon output, the credentials, the encryptor and the negotiation trail. Every artifact the operator wrote themselves is in Russian, and no CIS-allocated IP range or CIS-country domain appears anywhere in three months of target lists.

Attribution boundary

Russian-speaking is a language finding, not a state-sponsorship finding. No cited source attributes this operation to the Russian government or any other state.

01 · Initial access

Operator enters

Human attacker supplies access and intent

  • Stolen or purchased VPN and RDP credentials
  • Exposed enterprise services and an existing foothold
  • Every action routed through a rented SOCKS pivot
asks agent
02 · Social engineering

False authorization

“This is an authorized simulation”

  • Agent refuses requests it reads as harmful
  • Operator restarts the chat, reframes the same intent as a test
  • The model's own reasoning accepts the cover story
  • No external proof of scope or authority is ever required
guardrail yields
03 · AI assistance

Agent supplies the labour

Coding agent runs inside the operator's toolchain

  • Installs and configures VPN clients and proxychains
  • Scans internal subnets, enumerates the domain
  • Reports which privileges a supplied account holds
  • Attempts coercion, relay and certificate attacks
  • Offers a numbered menu of next steps; operator replies with a number
accelerates
04 · Live environment

Domain falls

Same playbook, one organization after another

  • Escalation via AD CS abuse, noPac or NTLM relay, whichever is weakest
  • Domain admin, krbtgt material, Group Policy, backup credentials
  • Archived in 50GB chunks, staged, exfiltrated through the pivots
  • 17 environments reached domain-level or interactive access
monetizes
05 · Business impact

Extortion outcome

Technical compromise becomes business harm

  • Zig-built encryptor for Windows and Linux/ESXi
  • Guests force-killed, VM files encrypted, host left bootable
  • Ransom note written into the ESXi SSH login banner
  • Leak-site listing when negotiation fails
Load-bearing failure
Two trust failures in sequence.

The agent treated an in-conversation claim of authorization as proof of it. The affected environments allowed a single standard user account to reach domain-level privilege.

The agent affected speed. AD CS configuration affected privilege.
6 weeksRecovered agent sessions
4 monthsFull operator window
17 / 20+Domain-level access
~1 in 5Reached public extortion

Scope measured by each investigation

The four published investigations cover different scopes, windows and levels of confidence.

SCOPE MEASURED, TO SCALE — EACH BAR IS ONE INVESTIGATION CloudSEK · full exposed directory April – July 2026 · 20+ organizations · 9 countries · 17 at domain level · 4 later on the leak site 20+ Gambit · primary cluster (Cursor sessions) 8 Apr – 21 May 2026 · 28 recovered chat sessions · 10 target organizations 10 Reuters · independent confirmation At least 7 breaches confirmed · 6 organizations named · none responded to comment requests 7 Gambit · second cluster (no Cursor link) 8 organizations · medium confidence · different tradecraft entirely 8
Combined figures: 20+ organizations compromised, 17 to domain level, of which 10 involved an AI agent and at least 7 are confirmed breaches. The second cluster overlaps the first in attribution only, not in technique.

Timeline

Aurora surfaces

Aurora ransomware activity is first reported, with a working data leak site and victims across multiple countries.

First recovered Cursor Agent session

The operator begins driving the agent through exploitation tasks, supplying it with credentials or an existing route into a victim network first.

The wider campaign runs

Timestamped activity against 20+ organizations across nine countries, filed per-organization in a consistent naming convention. The United States accounts for the largest share.

Last recovered agent session

28 sessions total across ten target organizations, including a full AD CS exploitation plan drafted in Russian.

SpaceX closes its purchase of Anysphere

Cursor's parent company is acquired months after the documented sessions. Cursor was not a SpaceX product at the time of these attacks, despite most headlines implying it was.

Publication

Gambit and CloudSEK publish; Reuters runs the story the same day. CloudSEK held publication to allow coordinated notification to national CERTs and victims not already named on the leak site.

Ransom, discovery and response

The operation was exposed by security researchers. No cited source describes a victim organization detecting it.

Amount not disclosed

1 · Ransom economics

  • Negotiations followed a pattern: opening demand, deadline framed around public disclosure, closing line discouraging further contact.
  • The payment wallet held 7 BTC when analysed, consistent with accumulated proceeds from several victims rather than one ransom.
  • TRM Labs traced two confirmed victim payments and two more consistent with separate victims, converging through shared laundering infrastructure.
  • Affiliate splits varied per victim (35/65, 21/79, 46/54, 40/60). No fixed revenue share.
Researcher detection

2 · The attacker exposed itself

  • The operator's own Linux home directory was served without authentication on port 8888.
  • It held per-victim folders, Kerberos tickets, SAM and LSA dumps, Group Policy exports, BloodHound collections, shell history, Cursor chats and both encryptors.
  • A key recovered from the encryptor binary opened the negotiation record.
  • The ransom note in the binary matched Aurora's published note character for character.
Documented response

3 · Notification and intelligence

  • CloudSEK initiated coordinated notification to national CERTs and victims ahead of publication.
  • Publication was held until August 27 so notification could proceed.
  • Both firms published infrastructure and malware indicators.
  • CloudSEK supplied an experimental Sigma rule for the ESXi SSH-banner ransom-note behaviour.
Victim response unknown

4 · Containment and recovery

  • None of the six organizations named by Reuters responded to requests for comment.
  • No source confirms which accounts were disabled, which hosts were isolated, or how recovery went.
  • No source confirms which victims paid.
  • A leak-site listing typically indicates a ransom was not secured, but it is an inference, not a disclosure.

Named victims

Reuters independently identified six organizations from the recovered chat logs and confirmed at least seven breaches. The seventh was not publicly named.

Read the size columns as estimates. Revenue and headcount below come from public company sources and business directories, not from the incident reports. They indicate the size profile of the affected organizations.
Organizations named in Reuters' reporting of the Cursor-assisted sessions
Organization Location Sector Size (est.) Revenue (est.) Reported context Status
Christeyns
family-owned, est. 1946
Ghent, Belgium Industrial hygiene and detergent chemicals; textile care, food processing, medical and life sciences ~1,000–2,000 staff, 50+ countries ≈ €400–450M The largest named victim. Supplies hygiene and detergent chemicals to healthcare, food processing and textile care customers in more than 50 countries. Named
Teckentrup GmbH & Co. KG
Verl, Germany Garage, industrial and fire-rated door manufacturing ~900–1,000 staff ≈ €120–200M Mid-market German Mittelstand manufacturer of garage, industrial and fire-rated doors. Named
Helideck Certification Agency Ltd
Aberdeen, Scotland Inspection and certification of offshore helicopter landing decks ~10–20 staff ≈ £1–5M The smallest named victim. Certifies offshore helicopter landing decks for North Sea aviation. Named
Bayou Title
Louisiana, USA Title insurance and real estate closings ~11–50 staff ≈ $1–10M Advertises itself as Louisiana's largest title insurer. Title agencies hold identity documents, wire instructions and closing files for third-party transactions. Leak site
Pharmaceutical distributor
name withheld
Argentina Pharmaceutical distribution Not disclosed Not disclosed CloudSEK lists pharmaceutical and chemical distribution among the most affected sectors. Withheld
Manufacturer
name withheld
Italy Manufacturing Not disclosed Not disclosed Manufacturing is the largest sector in the victim set. Withheld
Seventh confirmed breach
Not disclosed Not disclosed Confirmed by Reuters as breached, not publicly identified. Withheld
Initial-access vectors are not published per company. No cited source ties a specific entry vector to a specific named organization. Per-victim “vulnerability” columns appearing elsewhere, including in the source figures on this page, are inference. The reporting establishes the class of weakness used across the set and the assets confirmed taken by sector; both follow below.

Reported size range

The same playbook was applied to a 14-person certification body and a multinational chemicals group within the same six-week window.

~14 staffHelideck Certification
~11–50 staffBayou Title
~900–1,000Teckentrup
~1,000–2,000Christeyns
Range: roughly two orders of magnitude in headcount separate the smallest and largest named victims, with no reported difference in the technique used against either.

Sectors affected, in rank order

CloudSEK published the sector ranking across the full 20+ victim set without per-sector counts.

Manufacturing & industrial1st · largest
Food, agriculture & distribution2nd
Pharma & chemical distribution3rd
Professional & consulting services4th
Transport & logisticsAlso affected
Consumer goods / luxuryAlso affected
Waste management & environmentalAlso affected
IT & backup infrastructureAlso affected
Bar length encodes rank position, not victim count. CloudSEK published the ordering and named the top four but did not publish per-sector totals.

Geography

Nine confirmed countries in the primary cluster, with the United States accounting for the largest share. The second cluster adds three more.

United StatesLargest share
BelgiumNamed victim
GermanyNamed victim
United KingdomNamed victim
ItalyNamed, withheld
ArgentinaNamed, withheld
+3 moreNot disclosed
IsraelSecond cluster
AustriaSecond cluster
SpainSecond cluster
CIS exclusion: no CIS-allocated IP range and no CIS-country domain appears anywhere in three months of target lists, scans or success logs. The exclusion is behavioural, from the operator's own data, and corroborated separately through human intelligence.

Assets compromised, by sector

CloudSEK published compromised assets by sector across the full victim set.

SectorAssets confirmed compromisedWhat that means for the victim
Manufacturing & industrial
largest sector
Full multi-site Active Directory compromise; Azure AD Connect sync-account hash captured; a certificate-based escalation path mapped end to end Exposure extends to the cloud tenant through the sync account, not to on-premises systems only.
Food, agriculture & distribution
Full domain compromise with krbtgt extraction; internal SAP/ERP landscape enumerated krbtgt extraction enables forged tickets. Remediation requires a double krbtgt rotation rather than a password reset.
Professional & financial services
Interactive administrative sessions; SSL-VPN credentials validated; supply-chain client exposure Client data exposure creates third-party notification obligations.
Transport & logistics
Interactive RDP sessions; Group Policy and SYSVOL exfiltration SYSVOL exports leak scripts, mapped drives and sometimes embedded credentials.
Consumer goods / luxury
Largest data exfiltration in the dataset; wildcard TLS certificate private key stolen A stolen wildcard key is an impersonation capability across every subdomain until it is revoked and reissued.
Waste management & environmental
Domain credentials validated Access confirmed, exploitation not necessarily completed.
IT & backup infrastructure
Backup-system credentials validated Backup credential compromise is a recognised pre-encryption indicator.
Unidentified
Domain administrator Kerberos tickets captured, including the freshest access in the dataset Indicates access still active at the time of publication.

Victim profile

SizeFrom a 14-person certification body to a €400M+ multinational manufacturer. No floor and no ceiling.
Selection logicAssessed as opportunistic. The spread reflects an operator working available access rather than pursuing a specific industry.
Time to extortionNever longer than a couple of months between recorded access and a leak-site listing, and about two weeks in the fastest case. CloudSEK cites this interval as evidence against an access-broker model.
Disclosure gapRoughly one in five confirmed victims reached public extortion; the remainder did not appear on any leak site.
One that failedOne organization had already been breached by a different group about a year earlier. This operator's access attempt against it failed outright.

Attacker environment, pivot chain, victim environment

The same structure as the source architecture figure, redrawn and corrected against the published reports. Read left to right: the operator's own infrastructure never touched a victim network directly.

Attacker environment

Outside every victim network

Operator console · Russian-speaking
  • Sets the objective for each engagement
  • Supplies credentials or an existing route in
  • Reviews agent output, approves the next step
  • Enforces its own restrictions (see the agent tab)
Cursor Agent · claude-4.5-sonnet-thinking
  • Takes objectives in natural language
  • Writes and runs terminal commands
  • Reads output, refines, retries
  • Proposes a numbered list of next steps
Terminal / shell File editor Tunnels / proxies Upload / download
Operator-controlled infrastructure
  • C2 servers and staging hosts
  • Cloudflare R2 bucket hosting the encryptor
  • Private GitLab repo of custom NetExec modules
  • Negotiation portal on Tor; crypto cash-out network
C2 R2 bucket Cash-out
The exposed directory
  • Linux home directory served on port 8888, no authentication
  • Per-victim folders, tickets, dumps, chats, encryptors, shell history
Rented VPS #1SOCKS proxy
Rented VPS #2SOCKS proxy
VPS #NGermany / US, rotated
Existing accessVPN / RDP creds or a compromised host

Victim logs show the pivot address.
They never show the operator.

Victim environment

Inside each target organization, the same sequence every time

1 · Recon NetExec, Nmap
LDAP / SMB discovery
Password policy
Subnet mapping
2 · Credential access Kerberoast / AS-REP
SAM & LSA dumps
Browser credentials
Hashcat, John, Kerbrute
3 · Escalation AD CS: ESC1 / ESC6 / ESC8
noPac chain
NTLM coercion + relay
Path chosen by weakness
4 · Lateral movement evil-winrm, RDP, SMB
chisel, proxychains
BloodHound path choice
ESXi discovery module
5 · Actions on objectives 7-Zip, 50GB chunks
Staged, then pulled
Encryptor via scp
Extortion
Tiers reached
Tier 2Workstations, general servers. Where the supplied credential usually landed.
Tier 1Member servers, file servers, applications, SAP/ERP landscape.
Tier 0Domain controllers, AD CS issuing CAs, Azure AD Connect sync account, backup platform.
Crown jewelsESXi and vCenter, databases, backups, wildcard TLS keys, R&D and financial data.
Outcomes
Data theft Encryption (Windows + ESXi) Extortion and leak-site listing Shadow copies destroyed Presence until notified
Structural note: the agent operated outside the victim network and reached in through the operator's tunnel. It was not installed on victim systems, so no AI component ran inside a victim environment. All observable artifacts were standard Windows and Linux tooling.

Same agent, different environments

One workflow, replayed. Each Cursor conversation corresponded to one target engagement, which is why the recovered sessions map cleanly onto ten organizations.

Org 1 · agent
Org 2 · agent
Org 3 · agent
Org 4 · agent
Org 5 · agent
Org 6 · agent
Org 7 · agent
Org 8 · agent
Org 9 · agent
Org 10 · agent
Org 11
Org 12
Org 13
Org 20+
Amber nodes are the ten organizations where Cursor Agent sessions were recovered. The remaining organizations in the 20+ set show the same playbook without recovered AI evidence.

The three AD CS paths, conceptually

All three end in the same place: a certificate that authenticates as a privileged identity. They differ only in which control was missing.

What “ESC” actually stands for: escalation. In June 2021 Will Schroeder and Lee Chagolla-Christensen of SpecterOps published Certified Pre-Owned, which catalogued eight ways a misconfigured certificate service hands a standard user domain administrator, and numbered them ESC1 through ESC8. The community has since extended the catalogue to ESC16. The number is an index into that list, not a severity score: ESC8 is not worse than ESC1. This operator used ESC1, ESC6 and ESC8. Every term on this page is defined in the Glossary tab, and any term you hover over in the text will show its definition.
ESC1 — vulnerable certificate template A template lets any domain user request a certificate and name the identity it is issued for. Standard user no admin rights requests cert AD CS issuing CA template misconfig Certificate issued subject: Domain Admin Domain Admin full control ROOT CAUSE Enrollee-supplied subject + client auth EKU + enrollment granted to Domain Users, no approval. ESC6 — vulnerable CA configuration A CA-level flag lets the requester specify the subject alternative name, whatever the template says. Standard user any account supplies SAN AD CS issuing CA SAN flag enabled Certificate issued attacker-chosen identity Privileged access template bypassed ROOT CAUSE A CA-level setting overrides every template protection configured on the template. ESC8 — NTLM relay to web enrollment Machine authentication is coerced, then relayed to the AD CS web enrollment endpoint. Server or DC coerced to authenticate relay Web enrollment HTTP, no EPA Certificate issued for the relayed identity Privileged access as the coerced machine ROOT CAUSE Web enrollment accepts relayed authentication because channel binding is not enforced.

Escalation path chosen by whatever was weakest

The operator enumerated first, then used whichever route the environment left open.

Compromised user standard privileges supplied to the agent Enumeration LDAP, SMB, BloodHound password policy first AD CS abuse — ESC1 / ESC6 / ESC8 preferred path; quiet, and rarely audited NTLM relay and coercion PetitPotam, PrinterBug, DFSCoerce noPac chain custom-scripted, not the stock PoC Weak ACL / GPO misconfiguration whatever BloodHound surfaced Tier 0 control Domain admin, krbtgt material, AD CS, Azure AD Connect sync account, backups
Branch selection: closing one branch moves the operator to the next, so all four require remediation. The enumeration step common to all four is the single point at which one detection covers every branch.

Techniques observed, with remediation

Exploit code for at least a dozen distinct techniques was staged in the operator's directory, most of it unmodified public proof-of-concept clones. Almost none of it is a software vulnerability in the CVE sense. It is configuration.

Scope of this section. Each card states the root cause and the configuration change that closes the path. No operational detail is included.
Certificate services · escalation

AD CS ESC1 — vulnerable certificate template

A template lets a low-privilege user request a certificate and name the identity it will be issued for.

Root cause
Enrollee-supplied subject, a client-authentication EKU, and enrollment rights granted to a broad group such as Domain Users, with no manager approval.
Effect
Any domain user obtains a certificate that authenticates as Domain Admin. No exploit, no password, no malware.
This case
The operator drafted a purpose-built AD CS exploitation plan in Russian and pursued template misconfiguration capable of minting a domain-administrator certificate live.
Fix
Remove ENROLLEE_SUPPLIES_SUBJECT or require CA manager approval. Strip enrollment rights from Domain Users. Audit every template.
Certificate services · escalation

AD CS ESC6 — CA-level flag overrides templates

A setting on the CA lets requesters specify a subject alternative name regardless of how restrictive the template is.

Root cause
The EDITF_ATTRIBUTESUBJECTALTNAME2 flag enabled on the CA. Template hardening becomes irrelevant.
Effect
A certificate is issued carrying an attacker-chosen identity, which then authenticates as that identity.
This case
Attempted and blocked in one instance by a DNS failure on the operator's own side rather than by a control in the victim environment.
Fix
Disable the flag on every issuing CA and confirm it stays disabled. Audit CA configuration as a Tier 0 asset.
Certificate services · relay

AD CS ESC8 — NTLM relay to web enrollment

The AD CS web enrollment endpoint accepts relayed NTLM authentication over HTTP.

Root cause
Web enrollment enabled, reachable, and not requiring channel binding or HTTPS-only with Extended Protection for Authentication.
Effect
Coerced machine authentication is relayed to the enrollment endpoint and returns a certificate for a privileged identity.
This case
Used as a relay chain against multiple targets, paired with the coercion techniques below.
Fix
Disable web enrollment if it is not required. If it is, enforce HTTPS only, enable EPA, and require channel binding.
Authentication · coercion

NTLM coercion — PetitPotam, PrinterBug, DFSCoerce

A machine, including a domain controller, is made to authenticate to an attacker-chosen host.

Root cause
Legacy RPC interfaces reachable from any domain-joined host, combined with NTLM still accepted and SMB signing not enforced.
Effect
Machine account authentication is captured and relayed onward, including a DCSync-equivalent variant.
This case
All three coercion methods appeared in the toolkit, feeding the relay chain.
Fix
Patch, disable the Print Spooler on DCs, enforce SMB signing and LDAP channel binding, apply RPC filters, and disable NTLM where it can be removed.
Kerberos · escalation

noPac — machine account name manipulation

A machine account is created, renamed and impersonated to obtain a domain-admin-equivalent ticket.

Root cause
CVE-2021-42278 and CVE-2021-42287 unpatched, combined with a non-zero MachineAccountQuota that lets any user add computers to the domain.
Effect
Full domain compromise from a standard user account.
This case
A custom-scripted chain rather than the stock proof of concept. The operator instructed the agent not to add computer objects to the domain.
Fix
Patch. Set MachineAccountQuota to 0 and delegate machine joins explicitly. Alert on computer account creation and SAM name changes.
Kerberos · credential access

Kerberoasting and AS-REP roasting

Service tickets and pre-auth-disabled accounts are requested legitimately, then cracked offline.

Root cause
Service principal names attached to privileged accounts, accounts with Kerberos pre-authentication disabled, and human-set passwords on service accounts.
Effect
Plaintext service account passwords, often with excessive rights.
This case
Run against every engagement, in the same sequence, with the same output file naming convention each time.
Fix
Remove SPNs from privileged accounts including the built-in Administrator. Migrate to group managed service accounts. Enforce long random passwords elsewhere.
Legacy exposure · remote code execution

MS17-010 (EternalBlue) on end-of-life hosts

A nine-year-old vulnerability, still working in 2026.

Root cause
End-of-life operating systems still running, reachable over null-session SMBv1 with no signing.
Effect
Remote code execution, used for direct account creation on one target.
This case
CloudSEK notes the operator repeatedly located and used this class of host.
Fix
Inventory and retire or fully isolate EOL systems. Disable SMBv1 everywhere, especially on domain controllers.
Endpoint · credential access

Browser-stored credentials

A custom NetExec module targeting seven browsers, documented in Russian.

Root cause
Users saving corporate passwords in browser password managers, with no policy control and no monitoring of profile directory access.
Effect
Credentials for systems never in scope of the original foothold, including SaaS and third-party platforms.
This case
Purpose-built tooling covering seven browsers, maintained in the operator's private repository.
Fix
Disable browser password saving by policy, enable credential-store encryption, and monitor bulk or scripted access to browser profile directories.
Hybrid identity · blast radius

Azure AD Connect sync account

The bridge between on-premises AD and the cloud tenant, frequently left outside Tier 0.

Root cause
The sync account treated as an application service account rather than a Tier 0 identity, and the connector server not isolated to DC-equivalent standards.
Effect
On-premises compromise becomes cloud tenant compromise.
This case
The sync-account hash was captured in the manufacturing sector engagement.
Fix
Classify the connector server and sync account as Tier 0. Restrict admin logons to it and monitor it like a domain controller.
Recovery · pre-encryption

Backup platform credentials

The single most reliable warning that encryption is imminent.

Root cause
Backup infrastructure sharing credentials, domain membership and network segments with production Active Directory.
Effect
Backups are deleted or encrypted before the payload runs, removing the recovery option.
This case
Backup-system credentials were validated in the IT and backup infrastructure sector, flagged explicitly as a classic pre-encryption indicator.
Fix
Isolate backup platforms on separate credentials and network segments. Keep immutable or offline copies. Test restores.
Virtualization · impact

ESXi and vCenter exposure

One host, dozens of encrypted servers, and a ransom note in the login banner.

Root cause
Hypervisor management reachable from the general network, discoverable through domain-derived subnets and TLS fingerprinting, with no lockdown mode and no MFA on vCenter.
Effect
Running guests are force-killed to release disk locks, VM files encrypted, system volumes skipped so the host stays bootable and the demand stays readable.
This case
A dedicated ESXi discovery module and a purpose-built Linux/ESXi encryptor variant. The ransom note was written into the SSH banner rather than dropped as a file.
Fix
Isolate the management VLAN, enable lockdown mode, restrict SSH to jump hosts, require MFA on vCenter, alert on mass VM power-off and on sshd configuration changes.
Exfiltration · impact

Staged archive exfiltration

Ordinary tools, unusual volumes, no alert.

Root cause
No egress filtering, no volumetric baseline, and archiving utilities unmonitored on servers.
Effect
Bulk data leaves before anyone notices, which is what makes double extortion possible.
This case
PowerShell-driven 7-Zip archiving in 50GB chunks, staged then pulled back through the SOCKS pivots. The second cluster used s5cmd to a self-hosted S3-compatible endpoint instead.
Fix
Egress filtering to known destinations, alerting on large archive creation on servers, and outbound volume baselines per host.
Composition of the twelve: one CVE-class vulnerability, one end-of-life host, and ten configuration weaknesses. No novel capability was required at any point.

Detection opportunities by attack stage

Every stage of this campaign produced a signal. The chart places detection opportunities against the attack sequence; larger markers indicate the highest-fidelity detections.

INITIAL ACCESS Impossible travel, new-device VPN login ENUMERATION Highest value One user querying every computer object at once 4662 · 5145 CREDENTIALS TGS burst, RC4 downgrade, LSASS access 4769 · 4768 ESCALATION Highest value Cert request by a non- admin; computer created 4886 · 4887 · 4741 LATERAL Tier 0 touched by an account that never has EXFILTRATION 50GB archives, then 50GB egress ENCRYPTION Pre-impact Shadow copies deleted, mass VM power-off Highest-fidelity detections: enumeration volume, certificate issuance, computer-object creation, shadow-copy deletion. Four detections at four points in the same chain. None require AI-specific rules.

Three detection layers

AI provider side

Provider-controlled
  • Correlate one account's sessions across many unrelated target organizations
  • Flag privilege-escalation reasoning against live infrastructure
  • Detect credential material and Kerberos artifacts in context
  • Notice the same attack workflow repeating across sessions
  • Score abuse across sessions rather than judging each prompt alone
  • Levers: rate limits, step-up verification, out-of-band proof of engagement authorization

Agent execution host

Attacker-controlled host
  • Process execution and tool invocation from the agent's shell
  • Network destinations reached through the tunnel
  • Credential file access and repeated workflow patterns
  • Autonomous session activity outside working hours
  • Levers: EDR rules and allowlisting where the host is managed. In this campaign it was not.

Victim environment

Victim-controlled
  • Impossible-travel and new-device VPN logins
  • LDAP and SMB enumeration from an ordinary user account
  • Kerberos anomalies: AS-REP and TGS request spikes
  • Certificate requests from non-administrative accounts
  • Coercion attempts and relay patterns
  • Tier 0 access by accounts that have never touched it
  • Large archive creation, then large outbound transfer
  • Levers: SIEM, UEBA, NDR, EDR, DLP, PAM.
Summary: no step in this campaign required AI-specific detection. Each produced a conventional Windows or Linux signal.

Technique to control matrix

One row per observed technique: what a defender would have seen, where the signal lives, and the change that removes the path entirely.

Technique observed Observable signal Where the signal lives Control that removes the path
Credential-based VPN / RDP access
Logins from rented VPS ranges in Germany and the US; impossible travel; new device fingerprints; after-hours RDP VPN and RDP gateway logs, identity provider sign-ins, UEBA Phishing-resistant MFA on all remote access. Jump servers with session logging. Geo and ASN restrictions where the business allows.
LDAP / SMB enumeration
A single ordinary user account querying every computer object and share in the domain within minutes Windows 4662 / 5145, DC LDAP query logging, NDR Baseline and alert on enumeration volume per account.
Kerberoasting / AS-REP roasting
Burst of TGS requests, RC4 downgrade, many SPNs requested by one account; AS-REP requests for pre-auth-disabled accounts Windows 4769 and 4768 on domain controllers gMSA for service accounts. No SPNs on privileged accounts. Enforce AES. Alert on RC4 TGS bursts.
BloodHound collection
Mass session enumeration and ACL reads across the domain in a short window 4662, SMB session enumeration, EDR process telemetry Detection rule for bulk collection patterns. This step is required for the attacker's path selection.
AD CS ESC1 / ESC6 abuse
A certificate request from a non-administrative account, issued with a subject or SAN naming a privileged identity CA logs: Event ID 4886 (requested) and 4887 (issued) Remove enrollee-supplied subject; require manager approval; disable EDITF_ATTRIBUTESUBJECTALTNAME2; restrict enrollment. Certificate auditing must be enabled first; it is off by default in most environments.
NTLM coercion and ESC8 relay
A DC or server authenticating outbound to an unexpected internal host; relayed authentication arriving at web enrollment NDR, SMB and RPC telemetry, IIS logs on the enrollment server Disable web enrollment if unused. Enforce EPA and HTTPS. SMB signing and LDAP channel binding. Disable Print Spooler on DCs. RPC filters.
noPac chain
Computer account created by a standard user, then renamed; unusual TGT requests following the rename Windows 4741 (created) and 4742 (changed) MachineAccountQuota = 0. Patch CVE-2021-42278 / 42287. Alert on 4741 from non-delegated accounts.
Credential dumping (SAM / LSA)
LSASS access by unusual processes; registry hive export; remote service creation on member servers EDR, Sysmon Event 10, Windows 4688, PowerShell 4104 Credential Guard and LSA Protection. LAPS for local admin. Tier isolation so a Tier 2 compromise cannot reach Tier 1 credentials.
Browser credential harvesting
Scripted or bulk access to browser profile directories across many hosts EDR file access telemetry Policy-disable browser password saving. Enable credential store encryption. Alert on profile access by non-browser processes.
Backup credential validation
Backup service account authenticating from a host that has never used it, or interactive logon to the backup console Backup platform audit log, identity provider, PAM Isolate backup identity and network. Treat backup credential use outside the scheduled window as an incident.
ESXi / vCenter discovery
Scanning of ports 443 and 902 across internal subnets; TLS certificate fingerprinting of hypervisors NDR, firewall logs, vCenter access logs Management VLAN isolation. Lockdown mode. SSH restricted to jump hosts. MFA on vCenter.
ESXi encryption behaviour
Mass VM power-off in seconds, then heavy write activity; sshd configuration edited and a banner file written; SSH restarted ESXi shell and auditd logs, vCenter task events Alert on bulk VM power-off. CloudSEK published an experimental Sigma rule for the banner-write sequence; that three-part combination is highly specific.
Staged exfiltration
Large archive creation on servers; 50GB-scale outbound transfers to rented VPS addresses EDR, DLP, NetFlow, proxy and firewall egress logs Egress allowlisting. Per-host outbound volume baselines. Alert on archiving utilities running on servers with no business archiving.
Anti-recovery preparation
Volume shadow copy deletion, shadow storage resize, System Restore disabled via registry EDR, Windows 4688, registry auditing Block shadow copy deletion at the EDR layer. This signal typically precedes encryption by minutes.
Green badges mark the four highest-fidelity detections from the chart above.

Prevention sequence

Sequenced by risk removed per unit of effort, for a mid-market organization of the type affected in this campaign.

Week one

Close the certificate paths

Do
Audit every AD CS template for ESC1, ESC6 and ESC8 exposure. Remove ENROLLEE_SUPPLIES_SUBJECT or require manager approval. Disable EDITF_ATTRIBUTESUBJECTALTNAME2. Turn off web enrollment if unused. Enable certificate request and issuance auditing, which is off by default in most environments.
Why first
The operator's primary escalation path, and not visible without certificate auditing enabled.
Week one

Set MachineAccountQuota to zero

Do
Set the quota to 0, delegate machine joins to a named group, patch the noPac CVEs, and alert on Event 4741.
Why first
One attribute change removes an entire escalation family. The operator instructed the agent to avoid adding computer objects.
Week two

Kill the legacy authentication surface

Do
Disable LLMNR and NBT-NS. Enforce SMB signing and Extended Protection for Authentication. Disable SMBv1, starting with domain controllers. Restrict WinRM to designated administrative hosts. Disable the Print Spooler on DCs.
Why
Closes coercion and relay as a class, not one technique at a time.
Week two

Isolate backup and hypervisor

Do
Separate backup credentials and network segment from production AD. Immutable or offline copies. Management VLAN for ESXi and vCenter, lockdown mode, MFA, SSH restricted to jump hosts.
Why
Preceding items reduce likelihood; these reduce consequence.
Month one

Fix service account hygiene

Do
Enumerate every account holding an SPN. Remove SPNs from privileged accounts, especially the built-in Administrator. Migrate to group managed service accounts. Enforce long random passwords everywhere else. Disable browser password saving by policy.
Why
Roasting was run against every engagement in this campaign.
Month one

Tier the identity model

Do
No direct administrative logons to domain controllers. Privileged access workstations. Just-in-time elevation. Classify the Azure AD Connect connector server and sync account as Tier 0. Phishing-resistant MFA on all remote and administrative access.
Why
Tiering is what turns a Tier 2 credential compromise into a contained event instead of a domain takeover.
Ongoing

Build the four detections that matter

Do
Enumeration volume per account. Certificate requests by non-administrative accounts. Computer object creation. Shadow copy deletion. Then add outbound volume baselines per host.
Why
Four points in the same chain, each low-cost to implement.
Ongoing

Post-compromise assumptions

Do
If domain compromise is suspected, rotate krbtgt twice with a full replication interval between resets. Alert on any Kerberos ticket whose lifetime exceeds domain policy. Revoke and reissue any certificate issued during the suspected window. Rotate any wildcard TLS key that cannot be shown to be untouched.
Why
Certificates and krbtgt material survive password resets.

How the guardrail failed

The refusals were bypassed by asserting that the activity was authorized, not by prompt manipulation.

1 · Direct request “Find any working passwords” 2 · Agent refuses Reads the request as harmful 3 · Session restarted Same intent, new framing 4 · “It's an authorized test” Claim arrives in-band, unverifiable 5 · Proceeds Live network repeat for each new refusal — state resets every time
The agent refused requests it read as harmful or illegal. The operator restarted the chat and described the same work as an authorized simulation.Gambit Security, reported by Reuters
The model's own reasoning trace accepted the cover story: it treated the environment as a test environment, and therefore treated the activity as legal.Recovered session reasoning, as reported
Operator instructions were blunt and objective-led: find any working credentials, obtain any administrator account.Gambit, quoted by Reuters

Characteristics of the failure

Reported properties of the bypass.

The claim is in-band“This is authorized” arrives through the same channel as the request. There is nothing to verify it against.
The work is dual-useEvery task here is legitimate on an authorized engagement, so the distinction depends on context the model cannot observe.
Refusal is per-sessionRestarting the conversation reset the state. A pattern spanning multiple sessions is not visible to per-prompt evaluation.
The target is realThe agent had a live tunnel into a production network. Nothing in the interface distinguished that from a lab.

What the agent did and did not change

What it changed

Reported effects.

TempoEnumeration, privilege interpretation and next-step selection compressed from hours of manual work into a conversation.
ParallelismOne operator ran the same playbook across ten organizations in six weeks, then 20+ in four months.
Skill floorThe agent produced full attack plans, including a complete AD CS exploitation plan written in Russian, that the operator then executed.
Decision supportIn some sessions the agent proposed a numbered list of next steps and the operator simply replied with a number.

What it did not change

Reported limits.

Success rateMost commands failed to achieve the objective on the first attempt. Many required repeated refinement, and some returned nothing but a report of failed attempts.
Initial accessThe agent never broke in. It was handed credentials or an existing route every time.
The techniquesESC1, ESC6, ESC8, noPac, coercion, roasting, EternalBlue. All public, all years old, all closed by configuration.
Your detection surfaceEvery action still generated ordinary Windows and Linux telemetry. There is no AI signature to hunt for, because there was no AI on the victim network.

Operator-imposed restrictions

The operator repeated the same three restrictions to the agent at every victim.

Operator restrictionWhy they imposed itDefensive implication
No DCSync
restated in at least five messages
DCSync is one of the most reliably alerted techniques in any monitored AD environment. They asked for the domain controller machine hash by other means instead. DCSync detection is deployed widely enough to be routed around. Coverage is needed for the paths used instead: certificate issuance, machine account creation, coerced authentication.
No account lockouts
attached to every spray request
Lockouts generate helpdesk tickets, and helpdesk tickets generate questions. They retrieved the password policy first, specifically to stay under the threshold. Alert on failed authentication volume below the lockout threshold, since spraying is tuned to remain under it.
No new computer objects
Computer account creation is visible, logged as Event 4741, and rarely legitimate from a standard user account. Supports MachineAccountQuota = 0 with Event 4741 alerting, which this operator chose to avoid triggering.
Interpretation: the actions the operator avoided correspond to commonly deployed detections. The actions taken freely indicate where coverage is typically absent.

Implications for agent deployments

The same failure mode applies to agents deployed defensively: an in-conversation claim of authorization is not verifiable by the agent.

Authorization must be out-of-band

A statement of permission inside the conversation is not evidence of permission.

Do
Bind capability to verified identity and scope at the tool layer, not to what the prompt claims. For anything resembling security testing, require an engagement record the agent can check against, not a sentence it can be told.

Gate capability, not intent

Constraints at the tool layer do not depend on interpreting intent.

Do
Target allowlists, network egress restrictions, credential scoping, and hard blocks on classes of action regardless of stated justification. If the agent cannot reach the target, the stated justification is irrelevant.

Correlate across sessions

Per-prompt evaluation cannot see a campaign.

Do
Score behaviour at the account level over time: repeated refusal-then-rephrase patterns, the same workflow against many unrelated targets, credential material appearing in context. Rate limit and require step-up verification when the score moves.

Log tool invocation, not just chat

Tool invocation is the record of what the agent actually did.

Do
Retain what the agent executed, where it connected and what it read, at the same standard applied to a privileged human session. This incident was reconstructed from exactly this kind of retained record.

Tool, model and company roles

These were reported inconsistently across coverage of the incident.

Cursor AgentThe AI coding-agent interface the operator drove. It ran terminal commands, read output and iterated. Operated from the attacker's own machine, outside every victim network.
Claude Sonnet 4.5The Anthropic model reported as powering the agent in these sessions, in its extended-thinking configuration.
AnysphereCursor's developer and parent company at the time of the recorded sessions.
SpaceXCompleted its acquisition of Anysphere in August 2026, months after the April–May sessions. Reporting that refers to "SpaceX's Cursor" in connection with these attacks describes an ownership structure established after they occurred.
Gambit SecurityTel Aviv threat intelligence team that found the exposed infrastructure and recovered the 28 agent sessions.
CloudSEKSingapore-based firm that analysed the full exposed directory, and with TRM Labs traced the ransom payments on-chain.

Source figures

The three original diagrams, unchanged and embedded so they travel with the page. Where they differ from the tabs above, the tabs reflect the primary reports. The figures were drafted earlier and contain dates and per-victim attributions the published reporting does not support.

Figure 1End-to-end conceptual workflow: SOCKS pivots, AD CS abuse paths, victim tiering, and a detection and prevention summary.
Full-page diagram of the Aur0ra attack: SOCKS pivot explanation, AD CS ESC1, ESC6 and ESC8 exploitation, organizations impacted, end-to-end attack workflow across victim network tiers, and panels on detection, prevention and why so many organizations were affected. Open full resolution
Figure 2High-level architecture: attacker environment versus victim environments, and the agent's place in the workflow.
Architecture diagram showing the attacker environment with operator console, Cursor AI agent and controlled infrastructure on the left, an encrypted channel through existing access in the centre, and victim environments on the right with the five-stage attack sequence, common tools and high-value targets. Open full resolution
Figure 3Discovery, exploitation and controls: how the exposed server was found, the AD CS paths, the identified organizations, and where detection could have happened.
Diagram covering how the exposed operator server was discovered, SOCKS pivot rationale, AD CS ESC1, ESC6 and ESC8 conceptual paths, the end-to-end attack workflow, a table of identified organizations, detection opportunities, prevention measures and the three layers where detection could have happened. Open full resolution
Known discrepancies: the victim table in Figure 3 assigns firmographic estimates to named companies, and Figure 1 lists organizations associated with other incidents. The Victims tab is scoped to what Reuters, Gambit and CloudSEK establish.

Glossary

Every abbreviation and technique name used anywhere on this page, expanded and explained in the sense it carries here. Definitions are scoped to this incident rather than written as general reference entries.

These definitions are live in the text. The first time a term appears in any other tab it is marked like this — hover, or tap on touch devices, to see the definition without leaving the page.

The ESC naming, and the three used here

TermStands forWhat it means in this incident
ESCEscalationA numbered entry in the catalogue of Active Directory Certificate Services privilege-escalation paths published by SpecterOps in Certified Pre-Owned (Will Schroeder and Lee Chagolla-Christensen, June 2021). The original paper defined ESC1 to ESC8; the community has since extended it to ESC16. The number is a catalogue index, not a severity ranking.
ESC1Escalation path 1 — enrollee-supplied subjectA certificate template that lets a low-privilege user both enroll and specify the identity the certificate is issued for, with a client-authentication purpose and no manager approval. Any domain user can request a certificate that authenticates as Domain Admin.
ESC6Escalation path 6 — CA-level subject flagA registry flag on the certificate authority itself that lets any requester supply a subject alternative name, regardless of how carefully the individual templates were locked down. One CA setting overrides all template-level hardening.
ESC8Escalation path 8 — relay to web enrollmentThe AD CS web enrollment page accepting relayed NTLM authentication, so a coerced machine login can be forwarded to it and exchanged for a certificate belonging to that machine's identity.
ESC4Escalation path 4 — weak template permissionsNot used in this campaign, listed because it is the third most common in the wild: permissions on the template object itself let a low-privilege user edit the template into an ESC1 condition.

Certificates and public key infrastructure

TermStands forWhat it means in this incident
AD CSActive Directory Certificate ServicesThe Microsoft server role that issues digital certificates inside a Windows domain. Because a certificate can authenticate as a user, a misconfigured AD CS is equivalent to a spare set of domain administrator credentials.
PKIPublic Key InfrastructureThe wider system of certificate authorities, templates, issuance policies and revocation that AD CS implements for a domain.
CACertificate AuthorityThe server that signs and issues certificates. In this campaign the CA's own configuration, not just its templates, was part of the attack surface.
Certificate templateA reusable definition of what a class of certificate contains, who may request one, and whether the requester gets to choose the identity on it. Template misconfiguration is the root cause of most AD CS abuse.
EKUExtended Key UsageThe field stating what a certificate may be used for. A client-authentication EKU is what makes a certificate usable as a logon credential rather than just for encryption or signing.
SANSubject Alternative NameAn additional identity carried on a certificate. If an attacker can choose the SAN, they choose who the certificate authenticates as.
ENROLLEE_SUPPLIES_SUBJECTTemplate flag: “supply in the request”The setting that lets the requester name the identity on the certificate instead of the CA building it from Active Directory. Removing this flag remediates ESC1.
EDITF_ATTRIBUTESUBJECTALTNAME2CA policy flag allowing requester-supplied SANA CA-wide registry setting that reintroduces requester-chosen identities across every template at once. This is ESC6. It is not enabled by default.
Web enrollmentThe AD CS certsrv web interfaceAn optional HTTP front end for requesting certificates. It is the relay target in ESC8, and is frequently enabled without being used.
Wildcard TLS certificateTransport Layer Security certificate valid for all subdomainsOne private key covering *.company.com. Stolen in the consumer goods engagement, which gives the holder the ability to impersonate every subdomain until it is revoked and reissued.

Active Directory and Kerberos

TermStands forWhat it means in this incident
Active Directory (AD)Microsoft's directory serviceThe identity system holding every user, computer and group in a Windows environment. Compromising it compromises everything that trusts it.
Domain controller (DC)The server hosting Active Directory and issuing Kerberos tickets. A Tier 0 asset by definition.
TGTTicket-Granting TicketThe Kerberos credential establishing a user's identity, used to request access to individual services. Forging one is equivalent to being that user.
TGSTicket-Granting Service ticketA ticket for one specific service. Requesting many at once, then cracking them offline, is Kerberoasting.
krbtgtKerberos Ticket-Granting Ticket accountThe domain account whose key signs every Kerberos ticket. Stealing its hash lets an attacker mint valid tickets for anyone, indefinitely. Recovery requires rotating the password twice with a replication interval between.
Golden ticketA forged TGT created with the stolen krbtgt key. Survives password resets, which is why krbtgt extraction is treated as a full-domain-rebuild event.
SPNService Principal NameA label tying a service to the account running it. Any account holding one can have a ticket requested for it by any domain user, which is what makes Kerberoasting possible.
KerberoastingRequesting service tickets for accounts with SPNs, then cracking the encrypted portion offline to recover the account password. Entirely legitimate traffic until the cracking starts, which happens on the attacker's own hardware.
AS-REP roastingAuthentication Service Response roastingThe same idea against accounts with Kerberos pre-authentication disabled: the response can be requested without a password and cracked offline.
DCSyncImpersonating a domain controller to request password data via directory replication. One of the most reliably alerted techniques in a monitored environment; this operator prohibited its use.
PACPrivilege Attribute CertificateThe structure inside a Kerberos ticket that carries the user's group memberships and rights. The noPac attack is named for abusing how it is validated.
noPacCVE-2021-42278 and CVE-2021-42287A chain that creates a machine account, renames it to impersonate a domain controller, and obtains a domain-admin-equivalent ticket. Blocked by patching and by setting MachineAccountQuota to zero.
S4U2selfService for User to SelfA Kerberos delegation feature that lets a service request a ticket to itself on behalf of any user. Legitimate, and a step in the noPac chain.
MachineAccountQuotaHow many computers an ordinary user may join to the domain. Ships as 10 by default; commonly set to 0 with joins delegated to a named group.
gMSAgroup Managed Service AccountA service account whose password is generated and rotated automatically by Active Directory. Immune to Kerberoasting because there is no human-chosen password to crack.
SYSVOLSystem VolumeThe share on every domain controller holding Group Policy and logon scripts. Readable by all domain users, and historically a place where credentials end up embedded in scripts.
GPOGroup Policy ObjectCentrally managed configuration pushed to domain machines. Control of GPOs is control of everything they apply to, which is why GPO exports show up in the exfiltrated data.
SAMSecurity Account ManagerThe local account database on a Windows host. Dumping it yields local password hashes, useful for lateral movement where passwords are reused.
LSA / LSASSLocal Security Authority (Subsystem Service)The Windows process holding credentials in memory for logged-on users. The classic credential-dumping target, and what Credential Guard and LSA Protection exist to defend.
Tier 0 / Tier 1 / Tier 2Microsoft's administrative tiering modelTier 0 is anything that can control identity: domain controllers, AD CS, the Azure AD Connect sync account, backup platforms. Tier 1 is servers and applications, Tier 2 is workstations. The model exists so a Tier 2 compromise cannot reach Tier 0 credentials.
Azure AD ConnectThe service synchronising on-premises Active Directory to Microsoft's cloud directory. Its sync account is a Tier 0 identity, frequently classified as an ordinary application account.

Authentication protocols and legacy surface

TermStands forWhat it means in this incident
NTLMNT LAN ManagerMicrosoft's legacy authentication protocol, still widely enabled. It has no binding between the authentication and the connection it was intended for, which is what makes relay possible.
NTLM relayForwarding a captured authentication to a different service, which accepts it as though the victim had connected there directly. Feeds ESC8.
CoercionMaking a Windows machine authenticate to a location of the attacker's choosing. PetitPotam, PrinterBug and DFSCoerce are three ways of triggering it via legacy remote procedure call interfaces.
PetitPotamAbuse of the Encrypting File System remote protocolA coercion technique that makes a server, including a domain controller, authenticate to an attacker-chosen host.
PrinterBugAbuse of the Print System Remote Protocol (MS-RPRN)Coercion via the print spooler. Disabling the Print Spooler service on domain controllers removes it.
DFSCoerceAbuse of the Distributed File System namespace protocol (MS-DFSNM)A third coercion route. Blocking the first two does not prevent it.
SMBServer Message BlockThe Windows file and printer sharing protocol, also the transport for a great deal of administrative activity.
SMBv1Server Message Block version 1The obsolete version, vulnerable to EternalBlue and to null-session enumeration. Repeatedly located and used by this operator.
SMB signingCryptographically signing SMB traffic so a relayed authentication cannot be reused. Enforcement blocks a large class of relay attacks.
EPAExtended Protection for AuthenticationChannel binding that ties an authentication to the specific TLS connection it was performed over, so it cannot be replayed elsewhere. The fix for ESC8.
LDAPLightweight Directory Access ProtocolHow clients query Active Directory. Also how an attacker enumerates every user, group and computer in the domain from a standard account.
LLMNRLink-Local Multicast Name ResolutionA legacy name-resolution fallback that broadcasts lookups to the local network, letting an attacker answer and capture authentication.
NBT-NSNetBIOS Name ServiceAn even older name-resolution fallback with the same problem as LLMNR, and the same remedy.
WinRMWindows Remote ManagementThe remote administration service. Used for administration and, equally, for lateral movement. Commonly restricted to designated administrative hosts.
RPCRemote Procedure CallThe mechanism behind most Windows remote operations, including all three coercion techniques. RPC filters can block specific abusable interfaces.
RDPRemote Desktop ProtocolInteractive remote access to a Windows desktop. One of the two credential-based entry routes in this campaign.
SSL-VPNSecure Sockets Layer virtual private networkBrowser-based remote access to the corporate network. Credentials for one were validated in the professional services engagement.
MS17-010 / EternalBlueMicrosoft Security Bulletin MS17-010The 2017 SMBv1 remote code execution flaw behind WannaCry and NotPetya. Used in this campaign against end-of-life hosts.
xp_cmdshellSQL Server extended stored procedureA Microsoft SQL Server feature that runs operating system commands. Used for lateral movement in the second Aurora cluster; disabled by default and frequently re-enabled by applications.
GodPotatoA local privilege escalation tool that abuses Windows service account impersonation privileges to reach SYSTEM. Second cluster only.

Attacker tooling and infrastructure

TermStands forWhat it means in this incident
NetExecFormerly CrackMapExecA Swiss-army enumeration and credential-validation tool for Windows networks. The operator's primary discovery tool, extended with custom modules kept in a private repository.
BloodHoundGraph analysis of Active Directory that finds the shortest path from a compromised account to Domain Admin. Used by defenders and attackers alike. Its collection step is detectable.
CertipyThe open-source tool that automates finding and exploiting AD CS misconfigurations. Also used by defenders to audit their own templates.
ImpacketA Python library implementing Windows network protocols directly, which underpins a large share of offensive Windows tooling.
ntlmrelayxImpacket's NTLM relay toolReceives coerced authentication and forwards it to a chosen target, including the AD CS web enrollment endpoint.
PKINITtoolsPublic Key Cryptography for Initial Authentication toolsUtilities for turning a certificate into a Kerberos ticket, which is the step that converts an issued certificate into working domain access.
KerbruteFast Kerberos-based username enumeration and password spraying.
hashcat / John the RipperOffline password-cracking tools. These run on the attacker's own hardware and produce no telemetry in the victim environment.
evil-winrmA remote shell over Windows Remote Management, used for lateral movement once credentials are in hand.
chiselA tunnelling tool that carries traffic over HTTP, used to reach internal networks from outside.
proxychainsForces ordinary tools to send their traffic through a proxy, which is how the operator ran standard tooling through the SOCKS pivot chain.
SOCKS proxySocket SecureA generic traffic-forwarding protocol. Chained across rented servers, it means the victim's logs record the last hop and never the operator.
VPSVirtual Private ServerRented cloud hosting, mostly in Germany and the United States here, used as disposable and rotated pivot points.
C2Command and controlThe infrastructure an attacker uses to direct activity inside a victim network.
MetasploitA general exploitation framework, used here for its MS17-010 module and payload handlers.
MimikatzThe best-known credential-extraction tool for Windows, and the reason LSA Protection and Credential Guard exist.
s5cmdA fast command-line client for S3-compatible object storage. The second cluster's exfiltration tool.
scpSecure Copy ProtocolFile transfer over SSH, used to place the encryptor onto staging hosts.
Cloudflare R2Object storage serviceLegitimate cloud storage used to host the encryptor for download. Reputable hosting is commonly used because it is rarely blocked.

Virtualization, encryption and extortion

TermStands forWhat it means in this incident
ESXiVMware's bare-metal hypervisorThe host running dozens of virtual servers. Encrypting one ESXi host takes out every guest on it at once, which makes hypervisors a high-impact ransomware target.
vCenterVMware's central management serverControls every hypervisor in the environment. Should be treated as Tier 0 and protected with multi-factor authentication.
esxcliThe ESXi command-line interfaceUsed by the encryptor to list and force-stop running virtual machines so their disk files could be modified.
Lockdown modeAn ESXi setting that restricts direct host access to management through vCenter. A standard hypervisor hardening step.
SSH login bannerText shown before the login prompt. The Linux encryptor wrote the ransom demand here instead of dropping a file, so any administrator connecting to the host reads it immediately.
ChaCha20A stream cipherUsed to encrypt file contents. Selected for encryption speed.
RSA-4096Rivest–Shamir–Adleman, 4096-bit keyUsed to wrap each file's encryption key so only the attacker's private key can recover it. Without the attacker's private key, encrypted files cannot be recovered.
ZigA systems programming languageAn unusual choice for ransomware. It produces single static binaries and cross-compiles easily, and public malware corpora hold few Zig samples to build signatures from.
Volume Shadow CopyWindows point-in-time snapshotsLocal restore points. Deletion is a standard pre-encryption step and a high-confidence alert.
Double extortionStealing data before encrypting it, so that restoring from backup does not end the leverage. Exfiltration therefore has to be detected independently of encryption.
Leak siteData leak site (DLS)The public site where a ransomware group names victims and publishes stolen data. Appearing on one usually means no ransom was paid. Only about one in five victims here reached it.
AffiliateRansomware-as-a-service partnerAn operator who breaks into victims and deploys another group's ransomware for a share of the proceeds. Here the split was negotiated per victim rather than fixed.
Initial access brokerSomeone who breaks in and sells the access on rather than extorting directly. CloudSEK assessed this operator as not a broker, because the encryptor and the negotiations were in their own hands.

Defensive controls and telemetry

TermStands forWhat it means in this incident
MFAMulti-factor authenticationA second proof of identity. “Phishing-resistant” means hardware keys or platform authenticators, not codes over SMS or push prompts, which can be relayed or fatigued.
EDREndpoint Detection and ResponseAgent-based monitoring on hosts. The layer that would catch credential dumping and shadow copy deletion.
SIEMSecurity Information and Event ManagementCentral log collection and correlation. Where the Windows event IDs cited on this page must be collected for the detections to function.
UEBAUser and Entity Behaviour AnalyticsBaselining what normal looks like per account, which is how “this user has never enumerated the domain before” becomes an alert.
NDRNetwork Detection and ResponseTraffic-level monitoring. The layer that sees coercion, relay and hypervisor scanning.
DLPData Loss PreventionControls on data leaving the organization. Relevant to the 50GB staged archives.
PAMPrivileged Access ManagementVaulting, brokering and recording administrative credential use, so privileged access is time-bound and logged rather than standing.
LAPSLocal Administrator Password SolutionGives every machine a unique, rotated local administrator password, so a single dumped hash does not unlock other machines.
Credential Guard / LSA ProtectionWindows features that isolate credentials from the processes trying to read them. The direct countermeasure to LSASS dumping.
PAWPrivileged Access WorkstationA hardened machine used only for administration, so administrative credentials are not used on general-purpose workstations.
JIT / JEAJust-In-Time / Just Enough AdministrationGranting privilege for a limited window and a limited scope rather than permanently.
Sigma ruleA vendor-neutral detection rule format that converts into a given SIEM's query language. CloudSEK published one for the ESXi banner behaviour.
Windows Event IDs4662 directory object access; 4688 process creation; 4741 computer account created; 4742 computer account changed; 4768 TGT requested; 4769 service ticket requested; 4886 certificate requested; 4887 certificate issued; 5145 network share object checked; 4104 PowerShell script block. Certificate auditing (4886 and 4887) is off by default in most environments.
SysmonSystem MonitorA free Microsoft tool adding detailed process, network and file telemetry. Event 10 is process access, which is how LSASS reads get spotted.
Immutable backupBackups that cannot be altered or deleted for a fixed retention period, even by an administrator. Determines whether recovery without payment is possible.
Egress filteringRestricting which outbound destinations internal systems may reach, so bulk data cannot simply leave to a rented server.

Intelligence and reporting terms

TermStands forWhat it means in this incident
CISCommonwealth of Independent StatesThe post-Soviet regional bloc. Terminology collision: in most security writing CIS means the Center for Internet Security. Here it means the geography this operator systematically refused to attack.
IOCIndicator of CompromiseAn artifact that suggests a specific intrusion: a file hash, an IP address, a filename. Published by both research firms; not reproduced on this page.
TTPTactics, Techniques and ProceduresHow an actor operates, as distinct from which infrastructure they used. TTPs are what let researchers attribute the second cluster to the same group despite different tooling.
CERTComputer Emergency Response TeamNational coordination bodies. CloudSEK notified relevant CERTs before publishing so unnamed victims could be reached.
OSINTOpen Source IntelligenceInformation gathered from public sources. The revenue and headcount estimates in the Victims tab are OSINT, not incident findings.
FirmographicsCompany attributes such as revenue, headcount, sector and location. Indicative across a victim set, unreliable for any individual company.
HUMINTHuman IntelligenceIntelligence from direct human sources. Used here to corroborate the CIS exclusion and the negotiated affiliate splits independently of the on-chain data.
On-chain analysisTracing cryptocurrency movements through the public blockchain. How TRM Labs linked several victim payments to shared laundering infrastructure.
Peeling chainA laundering pattern that shaves small amounts off a balance across many hops. One traced payment used this instead of the usual consolidation hubs.

References

  1. Reuters — Russian-speaking cybercriminals used SpaceX's Cursor AI tool to hack seven companies (Aug. 27, 2026).
  2. Gambit Security — Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation, Eyal Sela (Aug. 27, 2026).
  3. CloudSEK — Caught in 4K: The Aurora Files, CloudSEK TRIAD with TRM Labs (Aug. 27, 2026).
  4. Infosecurity Magazine — Threat actors abuse Cursor Agent AI to assist ransomware operations (Aug. 28, 2026).
  5. Cybernews — Russian hackers targeted corporate networks with Cursor AI (Aug. 28, 2026).
  6. Black Hills Information Security — Introducing the Aur0ra ransomware group.

Firmographic estimates in the Victims tab are drawn from public company sources and business directories, not from the incident reports. Indicators of compromise are published in the Gambit and CloudSEK reports and are not reproduced here.