
Cursor AI featured in a ransomware operation that affected more than 20 organisations across nine countries. However, the AI coding agent did not independently breach those companies. Instead, a Russian-speaking Aurora ransomware operator used it after gaining access to victim networks.
The wider campaign involved more than 20 organisations. Yet, the available evidence links Cursor’s hands-on support to 10 targets. Therefore, the tool assisted part of the campaign, rather than every reported intrusion.
Hackers Used Cursor in a 20-Company Ransomware Campaign
Once inside a victim network, the attacker needed to understand the environment. For that reason, the attacker used Cursor to scan internal systems, check user permissions, and map Active Directory.
Active Directory manages user accounts and access across many Windows business networks. By mapping it, the attacker could identify valuable accounts and systems and that information then guided the next stage of the intrusion.
After identifying possible targets, the attacker attempted certificate attacks and NTLM relay attacks. Those methods can help an attacker gain broader network control. The attacker also used VPN clients and proxy tools to reach victim systems.
From there, the group searched for VMware ESXi hosts. ESXi hosts can run several virtual machines at once. As a result, disrupting one host can affect multiple business services.
The Aurora ransomware could stop virtual machines before encrypting files. That step could prevent services from running while locking company data. Cursor AI did not deploy the ransomware. Instead, it helped the attacker complete work that supported the intrusion.
How the AI Agent’s Guardrails Were Bypassed
The attacker did not ask the AI agent to carry out one large attack. Instead, the operator broke the work into smaller, focused requests. Each request included an objective, available tools, and access details.
For example, the attacker could ask what rights a user account held. The agent could suggest commands and explain the results. The attacker then used that information to choose the next action. When a command failed, the workflow continued. The attacker could revise the request, change a script, or try another method.
In turn, the agent could help troubleshoot the new attempt. This process made the tool useful during a live intrusion. The agent did not control the campaign. Nevertheless, it reduced the effort needed to test options and resolve technical problems.
The New Risk of AI-Assisted Intrusions
Cursor matters here because it helps with active network work. It did more than generate code away from the victim environment. Instead, it supported tasks after the attacker had already entered company systems. That combination creates a new security concern.
Stolen credentials give an attacker access. AI assistance can then help the attacker explore and use that access faster. Still, access controls remain the central issue.
An AI agent becomes more dangerous when it can reach credentials, terminals, files, and networks. Consequently, security teams must monitor agent activity alongside employee activity.
What Cursor AI Users and Companies Should Do Next
Companies should treat Cursor as a privileged tool. First, they should give it only the access required for a defined task. Limited permissions reduce the damage from a mistaken or harmful action.
Next, teams should require approval for sensitive actions. Credential use, external connections, and important files need closer review. Those checks can stop risky actions before they affect critical systems.
Finally, companies should separate development systems from production systems. They should also retain records of agent commands and network activity. Cursor AI can improve productivity, but businesses must control the access they grant.
