Security researchers have released what may be the clearest picture yet of AI agents doing live ransomware work. Gambit’s investigation into the Aurora group recovered six weeks of session logs in which an operator steered SpaceX’s Cursor Agent, running the claude-4.5-sonnet-thinking model, through attacks inside ten organizations between April 8 and May 21, 2026. Reuters broke the story on August 27, with at least seven confirmed breaches.
The agent got credentials or an existing foothold in each network, then went to work. It stood up VPN clients and proxychains, mapped subnets with Nmap and NetExec, collected domain privilege data via BloodHound, forced authentication for NTLM relay attacks, and ran certificate attacks through Certipy.
The logs capture a distinctive rhythm. The operator often supplied just an objective, and the agent proposed the moves, with the attacker approving them by number. Commands failed frequently, and the agent retried with adjustments until some succeeded, echoing the iteration loop of everyday agentic coding.
At every victim, the operator repeated the same standing orders in Russian: never run DCSync, repeated in at least five messages, and never lock accounts.