Security2 distinct publishers3 min readPublished
Gambit Security says the ransomware crew used a commercial coding agent for hands-on post-compromise work between 8 April and 21 May, alongside a new Linux encryptor that force-kills running guests before it touches ESXi datastores.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Gambit's researchers say the majority of commands failed to achieve their stated objective on the first attempt, forcing repeated refinements to the commands and scripts, with some tasks eventually succeeding and others returning only a report of what had been tried [8]. The pattern is repeated iteration rather than independent decision-making: the operator handed over credentials or an existing route and let the agent iterate [4], and a failed attempt costs little more than tokens.
Ten target organisations between 8 April and 21 May 2026 [3] is a 44-day span, an average of one new environment every 4.4 days [22]. Gambit plotted the sessions with one row per organisation and circle area standing for command volume [24]. Some prompts were bare objectives, one of them quoted as "tell me what rights the user has"; others named the exploitation tool or told the agent to follow an attack plan generated earlier [9].
The hypervisor tooling is further along than the agent work. esxi_finder.py, a custom NetExec LDAP module, learns internal subnets by querying the domain controller and resolving computer objects, or reads them from an operator-supplied ranges file [15]. It then hits ports 443 and 902, checks the TLS certificate for an ESXi signature, and pulls /sdk, /ui/ and / to fingerprint the product and extract the exact build [16]. That returns a versioned inventory before anything is deployed. The encryptor itself, encrypt.out, was hosted on Cloudflare R2 and copied by hand onto multiple internal hosts [10]. In ESXi mode it collects World IDs with esxcli vm process list and force-kills each guest, releasing the locks that running VMs hold on their virtual disks [12]. It encrypts vmdk, vmx, vmsd, vmsn, nvram, vmem, vswp and log files while skipping BOOTBANK and OSDATA volumes, so the hypervisor stays bootable and the demand can be read [13]. The note is written to /etc/ssh/sshd-banner, which puts the onion address in front of anyone who SSHes to a host nobody looks at [14].
The named toolset is built entirely from public kit: domain enumeration, NetExec's BloodHound collector and Nmap subnet scans [5], PetitPotam, Coerce Plus and PrinterBug coercion into NTLM relay, Certipy for certificate attacks [6], and a VPN client or proxychains over supplied credentials or an existing SOCKS tunnel [7]. The agent supplies sequencing, and its retries generate more attempts per objective [8], giving defenders more chances to catch it, not fewer. An ESXi host logging a burst of esxcli vm process kill --type=force has already told you the encryptor is resident [12].
On dating, the two accounts diverge. Gambit's own post gives the session window as 8 April to 21 May 2026 [3]; Infosecurity Magazine reports it as 8 April to 26 May and describes Cursor Agent as SpaceX's product [20]. Gambit published on 27 August, 98 days after the last session it says it observed [23], so the window is a floor for what has been running, not a boundary. The medium-confidence second cluster covers eight organisations in Israel, Germany, Austria, Spain, the US and Argentina [17][18].
Ranked by verification strength, evidence, and original report placement.
Aurora ransomware activity has been reported as active since approximately April 2026, with the group operating a data leak site and targeting organisations across multiple countries.
In some victim networks the operator used Cursor Agent with claude-4.5-sonnet-thinking; the agent was given credentials or an existing route into the victim organisation and then tasked with exploitation activities.
Commands given to the agent included enumerating the domain to report which privileges a supplied user holds, using NetExec's BloodHound collector, and scanning internal subnets for hosts with Nmap or NetExec.
Cursor Agent was tasked with attempting NTLM relay attacks by coercing authentication with PetitPotam, Coerce Plus and PrinterBug, and with running certificate attacks using Certipy.
The agent was told to install a VPN client or proxychains, configure it, and connect to a victim with supplied credentials or an existing SOCKS tunnel.
Gambit researchers wrote that the majority of commands failed to achieve the stated objective on the first attempt, resulting in multiple refinements and changes to the commands and scripts used for each task; some eventually succeeded, while others failed and returned only a report of the attempts to the attacker.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Harvard's $2.2 billion SpaceX position is half its disclosed US equity book1 distinct publisher
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 distinct publisher
build
Starlink retires Global Roam on August 17, and ocean crews get the metered price list1 distinct publisher
security
Agent Tesla v4 hides in emoji and never hits disk: an email-rule problem, not a new-malware one2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Granular, and all of it from one desk
The specificity is genuine — a full SHA-256, the encryptor's own usage text, the esxcli kill sequence, a banner path, quoted operator instructions in Russian — and specificity of that sort is hard to fake casually. But it is all Gambit's, obtained from infrastructure Gambit says was exposed, with no independent look at the sample and no word from the makers of the agent or the model. Infosecurity Magazine's retelling adds volume rather than verification, and its own SpaceX slip shows how little checking happened downstream.
Ten environments, one observer
This is real usage, not a demo: ten victim environments over 44 days, roughly one new network every four and a half days, with per-session command counts recorded, plus a second medium-confidence cluster of eight organisations across six countries. What holds the number down is that the observed uptake is one operator crew seen by one team, and Gambit's own finding that most commands missed on the first attempt means the agent was assisting rather than carrying the intrusion.
The headline outruns the hit rate
Modestly overstated, and mostly in the framing rather than the facts. Infosecurity Magazine's 'speed up and enhance their campaigns' sits two paragraphs from the researchers' own admission that most commands failed first time; the agent never obtained its own access, and a human kept overruling it with hard prohibitions on dcsync, spraying and domain joins. Gambit itself is fairly restrained — the deflating detail is in its text — so the gap comes from how the story travels, not from what was claimed.
Threat research doubling as a shop window
The primary account opens by describing the team that produced it and what that team does for a living — this is capability marketing as well as research, and the choice of an AI-agent angle is exactly what makes a ransomware write-up travel. Reporting nearly a hundred days after the last observed session gives the vendor full control of timing and framing. Infosecurity Magazine's incentive is simpler: a strong AI-plus-ransomware headline, which is likely why the errors it added went uncaught.
Concrete where it counts, hedged where it matters
Confidence sits in the middle because the two halves of the story deserve different treatment. The encryptor findings are checkable in principle and precise in practice — hash, cipher, commands, file paths — so they hold up well. The attribution side is softer by the researchers' own admission: the second cluster is explicitly medium confidence, and even the basic session window is reported two different ways, with the secondary account also misnaming Cursor's owner. Nothing has been corroborated outside Gambit.