BoletimSecAugust 28, 2026🇵🇹Translated from Portuguese

Aurora Ransomware Affiliate Uses AI Assistant Cursor to Compromise Active Directory and VMware ESXi Servers

An affiliate of the Aurora ransomware group has leveraged artificial intelligence to plan and carry out attacks against corporate environments, with a primary focus on Active Directory and VMware ESXi servers.

The operation affected more than 20 organizations between April and July 2026. Investigators found that the threat actor relied on Cursor, an AI programming assistant, to develop commands, adjust exploitation techniques, and construct attack sequences targeting Windows infrastructure.

One of the main targets was Active Directory Certificate Services (ADCS). The operator used AI assistance to refine privilege escalation attacks and identify paths that could lead to administrative accounts or full domain control.

The campaign also featured exploitation of the noPac vulnerability and NTLM relay attacks using tools such as PetitPotam, PrinterBug, and DFSCoerce. In several environments these techniques enabled the attackers to reach domain administrator privileges.

After consolidating access, the criminals collected and compressed large volumes of data before exfiltration. The Aurora ransomware was then deployed across Windows, Linux, and VMware ESXi servers. The ESXi variant stops virtual machines before encryption to increase impact on virtualized infrastructures. On Windows systems the malware also attempts to delete shadow copies and disable recovery mechanisms.

Related articles

HabrRansomware & Extortion

7 Core Rules for Responding to Ransomware and Infrastructure Breaches

The article outlines practical first-response steps for organizations facing ransomware encryption or infrastructure compromise for the first time. It stresses isolating affected systems from the network without powering them down, preserving volatile data and logs, and avoiding premature cleanup or backup restoration. The guidance covers closing obvious compromised access paths, documenting observed facts and actions, and stopping further ad-hoc changes once containment is achieved. These measures help retain forensic artifacts that investigators need to determine the initial access vector and attacker movement. The rules are presented as a starting point for teams without formal incident response procedures.

AntiMalwareRansomware & Extortion

IT Elements 2026 to Stage IT Apocalypse Simulations and Critique Russian Vendors

The IT Elements 2026 conference has unveiled its full program, centering on business continuity after successful cyberattacks, infrastructure failures, or technological disasters. Scheduled for September 9-10 at the Serp i Molot cultural center in Moscow, the event will host over one hundred reports, discussions, demonstrations, and master classes. The opening plenary will examine whether the primary-backup data center model remains viable, if the 3-2-1 backup rule still protects against modern ransomware, and whether CIOs or CISOs should own cyber resilience. Practical sessions will demonstrate a full Microsoft migration in 60 minutes, moving Exchange and MinIO to Russian alternatives, and a detailed review of domestic hyperconvergence strengths and weaknesses. Comparative test results for routers, NGFW, and VM systems will be presented without marketing gloss. Additional tracks will cover monitoring of corporate AI models from GPU to prompt under FSTEC Order No. 117, OWASP Top 10 for LLM, and MITRE ATLAS, alongside real-world cases from Rosatom, Beeline, Sber, and T-Bank. Trubnaya Metallurgicheskaya Kompaniya will simulate a 48-hour IT outage and show how to restart operations in half a day.

BoletimSecRansomware & Extortion

LockBit Claims Breach of U.S. Bank, Sets September 2026 Deadline for Ransom Payment

The ransomware group LockBit has added U.S. Bank to its leak site, claiming to have stolen data from the financial institution and threatening to publish it unless a ransom is paid by September 3, 2026. U.S. Bank stated it is actively investigating the claims but has so far found no evidence of unauthorized network access or impact on internal systems. Lee Henderson, the bank's vice president of public affairs, confirmed that the institution is monitoring the situation and treating the allegations seriously. LockBit placed the bank's domain on its extortion portal on August 19 and has a history of resuming operations after a major international law enforcement disruption in 2024. The investigation remains ongoing, with the final scope depending on whether unauthorized access and data theft can be confirmed.

安全客Ransomware & Extortion

Sorry Ransomware Exploits cPanel Vulnerability to Directly Lock Linux Servers in Multiple Chinese Incidents

China's National Computer Virus Emergency Response Center has issued a warning about the Sorry ransomware, which targets exposed Linux web servers through a cPanel authorization vulnerability. The Go-based malware gains root access without any phishing or user interaction, disguises itself as the legitimate sshd process, and follows a six-stage attack chain that includes data exfiltration before encryption. It terminates databases, security tools, and backup services, then uses AES and RSA to encrypt files with a .sorry extension while demanding ransom via an encrypted communication tool. The campaign specifically affects small and medium-sized enterprises running cPanel on mainstream Linux distributions, including domestic Xinchuang systems. Attackers also scan internal networks for weak SSH credentials to spread laterally. The center urges immediate patching of cPanel, exposure reduction, strong passwords, offline backups, and avoidance of fake decryptors.