Most of the AI agent's commands failed on the first attempt, according to researchers who tracked the Aurora ransomware group between April and May 2026.
What happened
Members of the Aurora ransomware group used Cursor Agent, a tool that lets an AI model write code and run commands on its own, to help attack 10 organizations between April 8 and May 26, 2026, Infosecurity Magazine reported on August 28. The AI model running inside it was Claude Sonnet. Aurora's operators brought the agent in only after they had already broken in, handing it stolen login details or an existing route into the victim's network. From there they asked it to explore the network, install software that creates an encrypted remote connection, and forge security certificates. Aurora has been active since April 2026 and publishes victim names on a leak site.
Going deeper
Some of the instructions Aurora's operators gave the agent were simple questions, such as asking what access a particular user account had, according to the research. Others were detailed commands, telling it to build a map of every user, computer, and permission on the network, and to search the internal network for other machines. They also directed it to use freely available tools called PetitPotam, Coerce Plus, and PrinterBug, each of which tricks a Windows server into sending its login credentials to the attacker. Another tool, Certipy, exploits the way Windows issues digital certificates so an attacker can pose as a legitimate user. In several cases, the operators told the agent to follow an attack plan it had produced earlier. Most commands failed on the first try, and Aurora's operators rewrote the instructions and scripts repeatedly, with some tasks eventually working and others producing only a report of what had been attempted.
What was said
"The majority of the commands failed to achieve the stated objective on the first attempt, resulting in multiple refinements and changes to the commands and scripts used for each task," researchers wrote in findings published August 27, 2026. They described a group experimenting with AI tooling rather than one that had integrated it successfully, while noting that the experiment itself points toward where attackers are heading.
In the know
Aurora also released a new version of its ransomware built for servers running VMware, software that lets one physical server run many separate virtual computers at once. The new version searches the victim's network for ESXi, the VMware software that hosts those virtual computers, and for vCenter, the console administrators use to manage many ESXi servers together, Infosecurity Magazine reported. It encrypts the files that make up each virtual computer, scrambling them so they cannot be opened without a key, while leaving the host server able to start so the victim can still read the ransom demand. VMware is common in hospitals, which is why the American Hospital Association circulated federal guidance on attacks against it to its members. Researchers also linked a second group of eight victims in several countries, including the United States, to an Aurora operator with medium confidence.
The big picture
CISA and the FBI tell organizations running VMware servers to keep them updated, switch off services they do not need, keep management consoles off the public internet, and hold offline backups tested through full restoration, in their joint advisory on ransomware aimed at this software. Electronic health records, imaging archives, laboratory systems, and billing platforms frequently share a small number of physical servers, so encrypting at the server level takes down services that look separate on an organization chart. Restoration testing carries particular weight, since a backup of a virtual computer only helps if the organization can rebuild the environment it runs in. The published research does not name the ten organizations Aurora targeted or describe how they responded, and Aurora lists its victims on its own leak site.
FAQs
Why would attackers use a developer tool rather than purpose-built malware?
Coding agents run commands, write scripts, and adjust when something fails, which covers much of what an attacker does by hand once inside a network. Using legitimate software also avoids introducing a file that security tools would recognize.
Does a high failure rate mean AI-assisted attacks are not a concern?
It means the capability is uneven rather than absent. An attacker who can retry instructions until something works still reaches the goal, and the failures cost time rather than access. That matches other research finding AI is used to speed up known techniques rather than invent new ones.
Why is attacking the host server worse than attacking individual computers?
One compromised host affects every virtual computer running on it, so the attacker gets scale without moving between systems one by one. Security software installed inside each virtual computer cannot see or stop encryption happening on the server underneath.
Why would ransomware leave the host server able to start?
The victim needs a working system to read the ransom demand and negotiate. Leaving the server unusable removes that channel and lowers the chance of payment.
What should a hospital check about backups of its virtual computers?
Whether backups cover the host server's configuration and not only the virtual computers themselves, whether copies sit offline or in storage the network cannot alter, and whether a full restoration has been tested recently. Organizations regularly find during an incident that they can restore individual machines but cannot rebuild the environment those machines need.
