www.infosecurity-magazine.com 8/28/2026, 8:30:49 AM · external

Aurora ransomware gang uses SpaceX AI tool in new ESXi attacks

Aurora ransomware gang uses SpaceX AI tool in new ESXi attacks
CyberSIXT Evidence Panel
Primary Source gambit.security
Threat Actor

THE article discusses how threat actors associated with the Aurora ransomware group are exploiting SpaceX's AI Cursor Agent to enhance their operations. According to research by Gambit Security, these actors have utilized the AI tool for tasks like reconnaissance, installing VPN clients, and running certificate attacks against 10 victims between April and May 2026. Despite mixed results in achieving their objectives, the study showcases the evolving use of AI in cybercrime.

Additionally, the Aurora group has deployed a new variant aimed at ESXi environments, designed to encrypt virtual machine files while keeping the hypervisor operational. This new activity targets various global organizations, reflecting a broader trend in ransomware operations leveraging advanced technologies.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT