Aurora Ransomware Operators Used SpaceX's Cursor AI in Attacks Against 10 Targets
Source: The Hacker News Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's AI-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security.
The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its toolkit, shell history, and encryptor. The development is the latest example of how bad actors are relying on commercial AI tools to carry out cyber attacks, even as model providers implement more guardrails to prevent misuse.
The names of the affected companies were not disclosed, but Reuters said they were Christeyns, Teckentrup, Helideck Certification Agency, Bayou Title, an Argentine pharmaceutical distributor, and an Italian manufacturer. Full Story