THE Aurora ransomware, believed to be operated by a Russian-speaking group, targets VMware ESXi environments across multiple organizations. It uses a sophisticated infection chain that involves the manual deployment of a custom Linux payload to encrypt virtual machines, exploiting tools such as the Cursor Agent for AI-guided exploitation.
The threat actors gain access through compromised credentials, deploying tools from Cloudflare storage onto internal networks and then identifying hypervisors using a custom LDAP module. Their encryption method incorporates ChaCha20 and RSA-4096, leaving the hypervisor bootable to display ransom notes. Additionally, the group exfiltrates data to private cloud storage and monitors activity to ensure operational security.
To mitigate these threats, organizations are advised to enforce strict security protocols, including isolating ESXi interfaces and implementing multi-factor authentication.