Ransomware Gang Weaponises Popular AI Coding Tool in Fresh Attacks
Security researchers at CloudSEK and Gambit Security have uncovered evidence that the Aurora ransomware group is using Cursor, an AI-powered coding assistant, to help develop tools used in attacks against at least ten organisations. The findings came from analysing infrastructure exposed by the Russian-speaking cybercrime group, giving investigators an unusual look inside how attackers are adapting mainstream AI development tools for malicious purposes.
This case highlights a growing trend: cybercriminals are increasingly using legitimate AI coding assistants to speed up the creation of malware and attack infrastructure, lowering the technical bar needed to build effective tools. While the AI tool itself is not inherently malicious, its misuse shows how widely available technology can be repurposed by threat actors, making it harder for defenders to rely on the assumption that unsophisticated attackers pose less of a threat.
For small and medium businesses, the takeaway isn't to fear AI tools themselves, but to recognise that ransomware groups are becoming faster and more capable at building custom attack tools. This makes strong baseline defences—patching, backups, endpoint monitoring, and staff awareness—more important than ever, since attackers can now iterate on their techniques more quickly than before.