A Russian-speaking affiliate operating the Aurora ransomware has been directly observed relying on an AI coding assistant to plan and execute network intrusions. Research from CloudSEK, drawn from an exposed operator server, revealed activity against more than twenty organizations across nine countries between April and July 2026, with domain-level access achieved at seventeen; four victims have since appeared on Aurora's public extortion site. A separate investigation by Gambit Security found the same tooling used for hands-on exploitation against ten additional targets, and identified a further cluster, attributed with medium confidence, hitting eight more victims across Israel, Germany, Austria, Spain, the U.S., and Argentina.
The ransomware is cross-platform, built from a single Zig codebase for Windows and Linux/ESXi, with strong anti-recovery features. Researchers also traced ransom payments on-chain and uncovered a laundering network pooling proceeds from multiple victims, with the affiliate's cut varying per victim rather than following a fixed split. This indicates AI-assisted intrusion is an operational pattern within a sustained, financially significant campaign, not an isolated incident.
Immediate Priorities:
What UltraViolet Cyber is Doing
ADVERSARY PROFILE
ALSO
Aur0ra. No other widely reported aliases.
ATTRIBUTION
Russia (unconfirmed state affiliation; assessed Russian-speaking). Independent criminal affiliate, not state-sponsored.
ACTIVE SINCE
2026 (1+ years)
MOTIVES
Financial gain. Extortion. Data theft.
INDUSTRIES
Manufacturing, food and agriculture, professional services, logistics, consumer goods, waste management, and IT and backup infrastructure.
COUNTRIES
The United States, Germany, the Netherlands, Canada, the United Kingdom, etc.
Notable TTPs
The clearest window into Aurora's tradecraft came from CloudSEK's discovery of a misconfigured Linux server serving the operator's own home directory without authentication. It contained Kerberos tickets, credential dumps, Group Policy exports, BloodHound collections, shell history, AI-assistant chat logs, and the encryptor itself. This was an unusually complete operational picture that CloudSEK, partnering with blockchain analytics firm TRM Labs, used to trace ransom payments on-chain.
Initial access methods documented across reporting include credential-based entry, aggressive phishing/email-bombing, and vishing calls impersonating IT help desk staff to induce remote-access tool installation. Once inside, the operator routed all victim-facing activity through rented SOCKS pivots, then ran a consistent playbook: LDAP/SMB enumeration, credential-hash cracking, and privilege escalation via one of three paths: a custom-scripted domain-controller impersonation chain; Active Directory Certificate Services abuse; or NTLM relay coercion. Exfiltration used bulk archiving staged before deployment.
An AI coding assistant was used throughout the later stages of this workflow, drafting full exploitation plans (in Russian) and, according to a separate study by threat intelligence firm Gambit Security, directly executing offensive commands against victims when supplied credentials or an existing foothold. Tasking ranged from open-ended objectives to specific tool invocation, with the operator often simply selecting from AI-suggested next steps. Gambit's researchers noted that most agent-run commands failed on the first attempt and needed iterative correction, suggesting the tooling accelerates and lowers the skill floor for intrusion work without yet enabling fully autonomous compromise. Researchers also flagged a second, medium-confidence Aurora-linked cluster targeting eight more victims across six countries, separate from the previously documented activity.
The encryptor exists in matched Windows and Linux/ESXi builds compiled from one unusual-language source tree, a choice that limits the volume of existing malware signatures available to defenders. The Windows variant chains shadow-copy deletion and System Restore disabling; the Linux/ESXi variant force-kills every running VM before encrypting and writes its ransom note into the host's SSH login banner. Furthermore, on-chain tracing linked a recovered ransom payment to a broader laundering network moving proceeds from multiple confirmed and probable victims, with affiliate payout shares varying case-by-case rather than following a fixed ratio.
This case demonstrates that AI-assisted intrusion has moved from novelty to a repeatable component of an active, multi-victim ransomware operation. Techniques that once required specialist knowledge (such as Active Directory Certificate Services abuse, NTLM relay chaining, systematic domain enumeration) are now executable through natural-language tasking of a commercial coding assistant. The human operator in several documented cases did little more than select from AI-suggested next steps, which narrows the skill gap between low- and high-capability threat actors and makes advanced intrusion techniques accessible to a wider range of criminal operators than before.
The victim spread is also significant. More than twenty organizations across nine countries were affected in the primary cluster, spanning manufacturing, food and agriculture, professional services, logistics, and backup/IT infrastructure, while a second, related cluster added roughly eight more victims across six additional countries. This breadth indicates opportunistic, indiscriminate targeting rather than a narrow, sector-specific campaign. Stakeholders should not rely on sector prestige or perceived low profile as a proxy for risk since mid-market manufacturers and distributors were compromised just as readily as more visible targets.
The encryptor's design choices carry their own operational risk. Its deliberate targeting of ESXi and virtualization infrastructure, including forced termination of running virtual machines prior to encryption, means hypervisor environments are a primary objective rather than incidental damage. Organizations with heavy virtualization footprints (which describes most mid-size and large enterprises today) face outsized downtime risk if this variant reaches production environments. The use of an uncommon programming language for the encryptor also means fewer existing detection signatures exist for defenders to rely on, which may temporarily reduce the effectiveness of signature-based tooling.
Finally, on-chain tracing of recovered ransom payments confirmed that proceeds from multiple victims converged through shared laundering infrastructure, and that affiliate payout shares varied per victim rather than following a fixed ratio. This points to a financially mature, ongoing operation generating real and substantial revenue, not a short-lived or opportunistic one-off crew. Combined with the demonstrated use of AI tooling to compress the time and expertise needed for exploitation, this campaign should be read as an early indicator of how ransomware operations broadly are likely to evolve, making proactive hardening now more valuable than reactive response later. Notably, this pattern was independently corroborated by more than one security research team, reinforcing that it reflects a genuine operational shift rather than an isolated or unverified finding.