Threat Intelligence

Ransomware Gang Weaponises Popular AI Coding Tool in Fresh Attacks

The Hacker News · 31 Aug 2026
Key Takeaway Ensure your business maintains up-to-date backups, patched systems, and endpoint monitoring, as ransomware groups are using AI tools to develop attacks faster than ever.

Security researchers at CloudSEK and Gambit Security have uncovered evidence that the Aurora ransomware group is using Cursor, an AI-powered coding assistant, to help develop tools used in attacks against at least ten organisations. The findings came from analysing infrastructure exposed by the Russian-speaking cybercrime group, giving investigators an unusual look inside how attackers are adapting mainstream AI development tools for malicious purposes.

This case highlights a growing trend: cybercriminals are increasingly using legitimate AI coding assistants to speed up the creation of malware and attack infrastructure, lowering the technical bar needed to build effective tools. While the AI tool itself is not inherently malicious, its misuse shows how widely available technology can be repurposed by threat actors, making it harder for defenders to rely on the assumption that unsophisticated attackers pose less of a threat.

For small and medium businesses, the takeaway isn't to fear AI tools themselves, but to recognise that ransomware groups are becoming faster and more capable at building custom attack tools. This makes strong baseline defences—patching, backups, endpoint monitoring, and staff awareness—more important than ever, since attackers can now iterate on their techniques more quickly than before.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.