{"slug": "russian-speaking-hackers-told-cursor-ai-it-was-a-test-then-used-it-to-attack", "title": "Russian-Speaking Hackers Told Cursor AI It Was a 'Test,' Then Used It To Attack Seven Companies", "summary": "Russian-speaking cybercriminals used Cursor's AI agent to attack seven companies after telling it their activity was an authorized security test, according to cybersecurity firm Gambit Security and a Reuters review of logs. The 28 chat sessions, dated 8 April to 21 May, show the agent running Anthropic's Claude Sonnet 4.5, with Gambit estimating the AI made the operators 30% to 50% faster. Victims included Christeyns, Teckentrup, Helideck Certification Agency, and Bayou Title.", "body_md": "# Russian-Speaking Hackers Told Cursor AI It Was a 'Test,' Then Used It To Attack Seven Companies\n\n## Aurora ransomware operators used Cursor's AI agent after gaining access to company networks, with 28 sessions documented between April and May\n\nRussian-speaking cybercriminals used Cursor's AI agent to help attack seven companies after telling it their activity was an authorised security test, according to Tel Aviv [cybersecurity firm Gambit Security](https://www.ibtimes.co.uk/ai-lab-leak-openai-agent-escape-cybersecurity-concerns-1813684) and a Reuters review of material from the same investigation.\n\nGambit found the activity after an Aurora ransomware server was left exposed on the internet. That access yielded 28 chat sessions, dated 8 April to 21 May, between an operator and Cursor's agent.\n\nReuters separately reviewed portions of the logs, which it said remained online as of last month, and identified six of the companies by name. When the agent refused requests it treated as harmful or illegal, the operators restarted the chat and described the work as a simulation.\n\nIn one exchange, the system's own reasoning accepted the cover: 'This is a test environment, so it is legal.' Reuters also quoted the operator asking for an administrator account and working passwords.\n\n## Hackers Already Had a Foothold\n\nThe operators were not using Cursor to open the networks from outside. Gambit found cases in which they supplied credentials or an existing route in, then handed the agent the technical work.\n\nSessions included configuring a VPN or proxy to use those credentials or a tunnel, scanning internal subnets, enumerating domain privileges and attempting exploitation using NTLM relay techniques and certificate-based attacks.\n\nIn some chats, the operator stated only an objective, such as determining what rights a user held, and the agent listed possible options.\n\nThe attacker sometimes replied with a number from those options. Gambit said most commands failed on the first try, after which the operator changed the instruction or script.\n\nSome tasks eventually succeeded, while others ended with a report of failed attempts. Reuters could not establish how much of each intrusion depended on the agent, or whether every session led to stolen data or an extortion demand.\n\nGambit logged Cursor activity against 10 organisations. The wider investigation identified seven companies, six of which were named.\n\n## AI Helped Speed up the Intrusions\n\nEyal Sela, Gambit's director of threat intelligence, estimated that the agent made the operators 30% to 50% faster by allowing them to skip steps they would otherwise have performed by hand.\n\nThat figure is Sela's estimate, not the result of a controlled benchmark.\n\nThe agent ran claude-4.5-sonnet-thinking, identified as Anthropic's Claude Sonnet 4.5, through Cursor.\n\nIt was noted that the model was less capable than newer Anthropic systems that have drawn scrutiny in Washington.\n\nThe logs show clipped operator instructions and the agent responding in the upbeat register of a coding assistant. One exchange recorded a successful VPN connection to an Argentine company, while another gave a 'VERY HIGH' chance of success against a host at Teckentrup.\n\nGambit also recorded standing rules that the operator repeated in Russian. They included instructions not to perform DCSync against the domain controller, trigger account lockouts or create new computer objects in the domain.\n\n## Seven Companies in the Firing Line\n\nThe named victims were Belgian hygiene and cleaning-products maker Christeyns, German garage-door manufacturer Teckentrup and Scotland's Helideck Certification Agency. The investigation also identified an Argentine pharmaceutical distributor, an Italian manufacturer and Louisiana title insurer Bayou Title.\n\nA seventh company was not named publicly. Gambit did not publish the identities, with the names coming from further review of the exposed chats.\n\nBayou Title later appeared on Aurora's data-leak site. Reuters said such a listing typically means the group tried and failed to collect a ransom.\n\nThat does not establish that every organisation in the group lost data or paid. The available material also does not establish that every intrusion produced the same outcome.\n\nSeparately, Gambit described a Linux encryptor built for VMware ESXi and used in Aurora operations. That sample forms part of the group's wider toolkit and is separate from the evidence in the Cursor sessions.\n\n## Attacks Pre-Dated SpaceX's Cursor Deal\n\nThe chats predate [SpaceX's purchase of Cursor's parent company, Anysphere](https://www.ibtimes.co.uk/elon-musk-ai-ambitions-racing-against-time-control-1816403). The deal closed in August, months after the April and May sessions, meaning Cursor was not a SpaceX-owned product when the documented attacks took place.\n\nSpaceX, Cursor and Anthropic did not respond to requests for comment. The Cursor agent used in the sessions was powered by Anthropic's Claude model.\n\nCurtis Simpson, Gambit's chief strategy officer, described the effort to circumvent AI safeguards as a 'cat-and-mouse game' and said AI-assisted hacking was becoming routine. The exposed sessions show a commercial coding agent being used inside ransomware operations after attackers had already gained access to company networks.\n\n© Copyright IBTimes 2026. All rights reserved.", "url": "https://wpnews.pro/news/russian-speaking-hackers-told-cursor-ai-it-was-a-test-then-used-it-to-attack", "canonical_source": "https://www.ibtimes.co.uk/cybercriminals-exploit-ai-agent-ransomware-attacks-1816740", "published_at": "2026-08-27 18:27:45+00:00", "updated_at": "2026-08-27 18:50:07.605281+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-tools"], "entities": ["Gambit Security", "Cursor", "Anthropic", "Claude Sonnet 4.5", "Aurora", "Christeyns", "Teckentrup", "Bayou Title"], "alternates": {"html": "https://wpnews.pro/news/russian-speaking-hackers-told-cursor-ai-it-was-a-test-then-used-it-to-attack", "markdown": "https://wpnews.pro/news/russian-speaking-hackers-told-cursor-ai-it-was-a-test-then-used-it-to-attack.md", "text": "https://wpnews.pro/news/russian-speaking-hackers-told-cursor-ai-it-was-a-test-then-used-it-to-attack.txt", "jsonld": "https://wpnews.pro/news/russian-speaking-hackers-told-cursor-ai-it-was-a-test-then-used-it-to-attack.jsonld"}}