All incidents

Aurora ransomware targets VMware ESXi with custom Linux payload

malwareopenAug 28, 2026 — Aug 30, 2026
Aurora ransomware targets VMware ESXi with custom Linux payload

AURORA ransomware has been observed deploying a custom Linux payload against VMware ESXi hypervisors, encrypting virtual machines while leaving the boot process intact to display ransom notes. The campaign, attributed to the group tracked as APT17, leverages compromised credentials and abuses the Cursor Agent AI tool to guide its intrusion steps. Researchers first highlighted the activity in a detailed analysis published by Gambit Security, with additional coverage noting the ransomware’s impact on multiple organisations reported by SecurityOnline.

Technical detail: The attackers first obtain valid logon details, then pull additional tools from Cloudflare storage onto the target network. Inside the network they run a custom LDAP module to discover ESXi hosts and subsequently drop a Linux‑based encryptor that uses ChaCha20 for file encryption and RSA‑4096 to protect the keys. The ransomware leaves the hypervisor kernel operational so that the boot loader can show the extortion message.

The encryption routine targets VMDK, VMX and related configuration files, appending a random extension before locking them. Victims receive a ransom note demanding payment in cryptocurrency, with a threat to publish exfiltrated data if demands are not met. The payload also establishes a reverse tunnel to a private cloud bucket where stolen virtual machine images and configuration data are uploaded for double extortion, a tactic highlighted in the same Gambit Security research analysis.

Context: According to Gambit Security’s analysis, the Aurora group has used the Cursor Agent for tasks such as reconnaissance, installing virtual private network clients and attempting certificate‑based attacks against at least ten organisations between April and May 2026. Although the AI tool did not guarantee success in every case, its adoption marks a clear shift toward automation in ransomware operations. The activity aligns with APT17’s historical focus on espionage‑style intrusions, now repurposed for financial gain, as noted in a separate report by Infosecurity Magazine.

Broader significance: The misuse of an AI coding assistant in a ransomware chain illustrates how legitimate productivity tools are being weaponised to lower the technical barrier for attackers. Security researchers warn that similar abuses could spread to other management platforms, prompting vendors to tighten API controls and monitor anomalous usage patterns. The trend also highlights the growing convergence of state‑linked tactics with cybercrime monetisation models, a development that demands closer collaboration between threat intelligence teams and software developers.

Defensive actions: Organisations should enforce multi‑factor authentication on all administrative accounts and review privileged access logs for unusual LDAP queries. Network segmentation must isolate ESXi management interfaces from general user traffic, and outbound connections to Cloudflare storage or unfamiliar cloud buckets should be blocked unless explicitly approved.

Additionally, security teams can disable or restrict the Cursor Agent within development environments, employ endpoint detection rules that flag the execution of unknown Linux binaries on hypervisors, and maintain offline, immutable backups of virtual machine disks to enable recovery without paying the ransom.

Intelligence briefing updated Aug 30, 2026

APT17
Root sourcegambit.security
Timeline Coverage

Swipe to explore timeline