Back Mezha.Ua Hackers used Cursor AI to hack into at least 10 companies - Межа
Since April, the Russian-speaking hacker group Aur0ra has been using artificial intelligence from the start-up Cursor AI – now owned by Elon Musk's company SpaceXAI – to carry out cyberattacks on at least 10 corporate networks. They used Cursor Agent, based on Claude Sonnet 4.5, "to facilitate practical use" within the targeted networks. This is reported by Cybernews.
According to a report by Gambit Security, the attacks took place between 8 April and 21 May 2026. Gambit stated that it was able to review 28 compromised chat sessions amongst other Aur0ra infrastructure, giving researchers insight into how the Cursor AI agent was utilised during a real-world cyberattack.
The researchers identified two attack chains: one involves Linux malware capable of compromising ESXi environments, whilst the other utilises attacker-controlled S3-compatible infrastructure for data collection.
First, the hackers deployed the Linux variant of their proprietary ransomware programme, Aur0ra – dubbed 'ESXi ransomware' – designed to encrypt VMware ESXi environments. Using Cursor with Claude Sonnet 4.5 in 'thinking' mode, the hackers first provided the AI-powered encryption agent with a set of credentials or a path to the victim organisation before assigning it 'standard exploitation tasks'.
These tasks included internal network scanning, privilege escalation, credential-based attacks, NTLM relay attempts and certificate-based attacks. In some cases, the hackers specified which tools or methods the agent should use; in others, the agent was given a target and complete freedom of action.
The Gambit report states that when commands failed to yield results, Cursor would repeatedly modify them or suggest alternative approaches depending on the victim's environment. At times, the agent would even provide Aur0ra members with a numbered list of possible steps from which they could select their actions.
Members of the Russian-speaking group also imposed restrictions on the agent, specifically instructing him not to carry out DCSync attacks, lock user accounts or create new computer objects within compromised domains.
The researchers noted that Cursor rejected some requests, flagging them as potentially malicious or illegal. However, according to Eyal Seli, Gambit's director of threat intelligence, these safeguards proved relatively easy to circumvent. Sela explained that the hackers "almost always circumvented the rejections by restarting the dialogue and insisting that the breach was part of a test".
Read also: More than 100 tech companies, including Google and OpenAI, have called for a "collective defence" against AI-powered cyberattacks
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
