Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Aurora ransomware has been tied to a Russian-speaking affiliate that used an AI coding assistant while targeting more than 20 organisations.

A wrongly exposed server gave investigators a detailed view of the operator’s activity, from intrusion to payment. The activity ran from April to July 2026 across nine countries.

The operator gained domain-level or interactive access at 17 targets, while four victims appeared on Aurora’s public leak site. Manufacturing, food, agriculture and professional services were affected.

CloudSEK said in a report shared with Cyber Security News (CSN) that the exposed directory contained the affiliate’s tools, command history, credential material, Cursor chat records and Aurora encryptor.

The evidence points to an affiliate conducting intrusions, rather than a broker selling access. The findings show how ransomware operations can combine familiar Windows network abuse with faster planning support.

Open Directory (Source - CloudSEK)
Open Directory (Source – CloudSEK)

The operator used rented SOCKS proxies to reach victim environments, then relied on tools for discovery, password attacks, credential theft, data theft and encryption-tool delivery.

Ransomware Hacker Uses AI

In its final weeks of recorded activity, the affiliate used Cursor to draft and refine attack sequences in Russian.

One extended session focused on exploiting weaknesses in Active Directory Certificate Services, a certificate-issuing feature, against a victim environment. The chats show back-and-forth planning rather than a generated command.

That matters because an assistant can help an intruder translate reconnaissance results into the next step quickly, even when the underlying tactics, such as those in AI-assisted ransomware operations, remain familiar to defenders.

The affiliate followed a repeatable playbook. It used NetExec to examine network services, retrieved password policy details, and attempted ASREPRoasting and Kerberoasting, techniques used to obtain password data for offline cracking. It also collected SAM and LSA information, Group Policy exports and BloodHound data.

The most heavily-worked AI-assisted engagement in the operator’s recovered chat history (Source – CloudSEK)

For deeper access, the operator used a custom noPac route, certificate-service abuse and NTLM relay attacks triggered with PetitPotam, PrinterBug and DFSCoerce.

Organisations should review Active Directory credential theft warnings closely, because control of the domain can expose accounts, systems and recovery options across a network.

Target lists and logs did not contain CIS-allocated IP ranges or CIS-country domains, according to the researchers.

Although that pattern alone does not identify a person, the operator’s own notes, custom tool documentation and AI planning sessions were written in Russian, reinforcing CloudSEK’s assessment.

Encryption and Defence Steps

Aurora’s Windows and Linux or ESXi lockers were built from one Zig codebase, an uncommon choice for ransomware.

The Windows sample was named sap.exe, while the Linux and ESXi build was encrypt.out. Both were downloaded from a public Cloudflare R2 bucket and copied to staging hosts via scp.

On Windows, the malware attempts to remove volume shadow copies, resize shadow storage and disable System Restore before encrypting files.

The ESXi mode kills running virtual machines and encrypts virtual-machine files, making ESXi ransomware attack risks especially disruptive because it can affect several business systems. The recovered negotiation data also showed that at least one victim settled a ransom demand.

CloudSEK and TRM Labs traced the payment and identified two confirmed victim payments plus two further payments consistent with separate victims, which moved through shared laundering infrastructure before reaching cash-out.

Defenders should disable LLMNR and NBT-NS, use SMB signing and Extended Protection for Authentication, restrict WinRM to approved administrative hosts, and remove SMBv1 where it remains.

They should examine certificate templates for risky settings and log certificate requests and issuances to catch abuse early.

Teams should rotate the krbtgt password twice, with full replication between resets, after a suspected domain compromise.

They should protect browser-stored credentials, use separate credentials and network segments for backups, and isolate or retire older systems.

Securing virtualisation management interfaces, as stressed in ransomware platform targeting ESXi, can limit the impact of an encryption event.

Indicators of compromise (IoCs):-

Type Indicator Description
Onion address ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion Aurora Tor negotiation site
SHA-256 eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207 sap.exe Windows locker
SHA-256 a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe encrypt.out Linux and ESXi locker
Filename !!!README!!!DO_NOT_DELETE.txt Aurora ransom note
IPv4 172.86.113.245 Operator VPS
IPv4 172.86.90.75 Operator VPS
IPv4 144.172.116.150 Operator VPS
IPv4 104.194.134.167 Operator VPS used as SOCKS relay
IPv4 89.106.83.49 Rented SOCKS pivot
IPv4 23.234.108.48 Rented SOCKS pivot
IPv4:Port 167.88.167.37:50167 C2 egress check
IPv4:Port 45.61.148.166:21056 Rented SOCKS pivot

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations appeared first on Cyber Security News.