Russian Hackers Used SpaceX’s AI Coding Assistant To Conduct Attacks: Report

Russian Hackers Used SpaceX’s AI Coding Assistant To Conduct Attacks: Report


A Russian hacking group active since April has been using SpaceX’s AI coding assistant, Cursor, to conduct cyberattacks.

Reuters reported that the group used Cursor to break into a Belgian chemical company. The wire service reported that the group had also launched successful attacks against at least six other firms.

Gambit Security identified the hacking group as Aurora in a report and detailed its activities.

“In a recent investigation, we identified exposed infrastructure associated with the Aurora ransomware group, providing visibility into the group’s operations across multiple victim environments,” the report states. “Aurora ransomware activity has been reported as active since approximately April 2026, with the group operating a data leak site and targeting organizations across multiple countries.”

The report details an Aurora operator using Cursor Agent, running Claude Sonnet, to assist with exploitation across ten target organizations between April 8 and May 21. Gambit said it then identified a second cluster of activity that it believed also was associated with Aurora.

“In some victim networks, the operator used Cursor Agent with claude-4.5-sonnet-thinking. In these cases, the agent was given credentials or an existing route into the victim organization. Then it was tasked with various exploitation activities,” the report states. “In some cases, the attacker only asked the Agent to achieve an objective, such as “tell me what rights the user has,” while in others, they told the Agent which exploitation tool to use or instructed it to follow a previously generated attack plan.”

Reuters reported that Gambit it discovered the hacking efforts after finding a server Aurora left exposed to the internet. The wire service reported that the Tel Aviv-based company then reviewed 28 chat sessions that occurred between Aurora hackers and Cursor AI agents.

The Gambit report states that most of the commands failed. However, the hackers then refined tasks and changed commands and scripts. “Some eventually succeeded in achieving the objective, while others failed and returned only a report of the attempts to the attacker,” the report stated.

These are some of the tasks that were given to the agent, based on the Gambit report:

  • Installing a VPN client or proxychains, then configuring it and connecting to a victim with supplied credentials or an existing SOCKS tunnel.
  • Scanning the internal subnets for hosts with Nmap or NetExec.
  • Enumerating the domain to report which privileges a supplied user holds, using NetExec’s BloodHound collector.
  • Attempting NTLM relay attacks by coercing authentication with PetitPotam, Coerce Plus, and PrinterBug, and using Impacket ntlmrelayx to relay the resulting authentication.
  • Running certificate attacks with Certipy.



Source link

Posted in

Amelia Frost

Leave a Comment