Aurora Ransomware Group Uses SpaceX AI to Hack Companies
The Aurora ransomware group used the Cursor AI coding assistant to accelerate cyberattacks against companies in seven countries between April and May 2026.
The Aurora ransomware group used Cursor, an AI coding assistant owned by Space Exploration Technologies Corp., to facilitate cyberattacks against multiple organizations between April 8 and May 21, 2026. The Russian-speaking cybercriminals targeted at least seven companies, including Christeyns in Belgium, Teckentrup in Germany, the Helideck Certification Agency in Scotland, and Bayou Title in the United States, as well as manufacturers in Italy and Argentina.
A report by Gambit Security revealed that the hackers bypassed safety guardrails by claiming their malicious activities were part of a legal simulation. Using the Cursor Agent powered by Anthropic's Claude Sonnet 4.5, the group performed tasks such as scanning internal subnets, enumerating domain privileges, and attempting certificate attacks. Gambit Security estimates the AI agent increased the hackers' operational speed by 30% to 50%.
Gambit Security discovered the campaign after Aurora inadvertently exposed a server containing 28 chat sessions between the hackers and the AI. These logs showed the hackers refining scripts after initial failures to achieve account takeovers and credential theft. Space Exploration Technologies Corp., Cursor, and Anthropic have not commented on the incident.