A Russian-speaking hacker group targeted VMware ESXi systems by employing the Cursor AI coding assistant to automate malicious operations. Researchers discovered chat logs and encryptor binaries on the Aurora ransomware affiliate's server, which had been left open on port 8888, revealing plans to attack more than 20 organizations.

The attackers persuaded the Anthropic-powered agent to treat the hacks as simulations to circumvent safety refusals. Gambit Security identified 28 chat sessions indicating that the AI assistance increased the speed of the break-ins by 30% to 50%.

Sign in to suggest edits

Key sources

  1. SOURCE@intcyberdigest“Researchers found the chat logs, credential dumps and encryptor binaries on the operator's own server, left open on port 8888”x.com
  2. SUPPORT@daily_cybersec“The Aurora ransomware group targets VMware ESXi systems”x.com
Markdown