Skip to content

other

Aurora

Ransomware crew tracked in threat intelligence reporting for extortion operations against enterprise infrastructure.

Known aliases

  • Aurora group

Relationships

No evidence-backed relationships are recorded.

Current clusters

build1 publisher

Aurora put a Cursor agent on the keyboard for its ESXi exploit work

GBHackers reports Aurora operators handing vulnerability analysis and payload delivery to Cursor agents against ESXi hypervisors, and Anthropic's September 2026 assessment describes the same delegation running for months inside state-linked campaigns.

Publishers:dev.to

Reality

Evidence24
Adoption42
Hype gap+38
Incentives55
Confidence30