Cybercriminals are increasingly turning to artificial intelligence to speed up attacks, with a newly uncovered campaign showing how ransomware operators can use commercial AI agents during intrusions.
The activity involved Aur0ra, a relatively new ransomware group, and targeted companies across several countries, according to cybersecurity firm Gambit Security and data reviewed by Reuters.
Gambit said the attackers used Cursor’s AI agent while carrying out operations against corporate networks.
The researchers discovered the activity after finding a server that had been inadvertently exposed online.
Inside were dozens of conversations between the hackers and the AI system.
The conversations suggested that the hackers attempted to persuade the AI that their activities were authorized simulations.
That distinction mattered because the AI had safeguards designed to prevent assistance with criminal activity.
When the system rejected some requests, the attackers reportedly tried again using different conversations and explanations.
The resulting interactions provided assistance with technical aspects of the attacks.
Gambit said the operation demonstrated the potential for AI to accelerate cybercrime by allowing attackers to obtain technical assistance without having to perform every step manually.
Among the companies identified by Reuters were Christeyns in Belgium, Teckentrup in Germany, the Helideck Certification Agency in Scotland and Bayou Title in Louisiana.
A pharmaceutical distributor in Argentina and a manufacturer in Italy were also identified.
The investigation did not establish that every target suffered the same consequences or that all attacks resulted in stolen information.
At least one company, Bayou Title, appeared on Aur0ra’s data-leak site, a development that can indicate an attempted ransomware operation.
The emergence of AI-assisted attacks presents a difficult challenge for cybersecurity teams.
Traditional defenses must now contend not only with human attackers but also with AI systems capable of rapidly generating technical assistance.
Experts expect the contest between AI developers and cybercriminals to intensify as both sides adapt.
