Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation

    Date: 08/28/2026

    Severity: High

    Summary

    The Aurora ransomware group has been observed targeting VMware ESXi environments with a Linux-based encryptor that uses ChaCha20 encryption and RSA-4096 key wrapping. Attackers also abused Cursor Agent with Claude Sonnet to automate hands-on-keyboard exploitation, including internal reconnaissance, credential abuse, NTLM relay, and certificate attacks across multiple victims. A separate Aurora activity cluster used SQL Server xp_cmdshell, GodPotato, DCSync, and S3-based data exfiltration, demonstrating sophisticated ransomware, lateral movement, privilege escalation, and cloud exfiltration techniques. 

    Indicators of Compromise (IOC) List     

    Domain/URLs

    exposedrecords.io

    ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion

    pub-c057b7d0b24944a29e381ce9ea22a2f1.r2.dev/xu4gid0t8er3.out

    IP Address

    104.194.134.167

    144.172.95.50

    146.19.125.36

    152.236.4.14

    157.173.29.133

    167.88.167.37

    172.86.113.245

    172.86.90.75

    217.69.8.54

    23.246.128.3

    45.142.31.17

    45.32.186.198

    45.59.113.63

    45.61.134.62

    45.61.148.166

    68.210.224.231

    77.110.125.143

    81.177.215.15

    89.106.83.49

    93.157.139.115

    93.157.139.123

    Hash

    a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe

    File Name

    !!!README!!!DO_NOT_DELETE.txt 

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "exposedrecords.io" or url like "exposedrecords.io" or siteurl like "exposedrecords.io" or domainname like "ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion" or url like "ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion" or siteurl like "ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion"

    Detection Query 2 :

    dstipaddress IN ("81.177.215.15","45.59.113.63","45.61.148.166","23.246.128.3","93.157.139.115","146.19.125.36","152.236.4.14","77.110.125.143","172.86.90.75","89.106.83.49","45.32.186.198","157.173.29.133","45.61.134.62","104.194.134.167","68.210.224.231","144.172.95.50","45.142.31.17","172.86.113.245","217.69.8.54","167.88.167.37","93.157.139.123") or srcipaddress IN ("81.177.215.15","45.59.113.63","45.61.148.166","23.246.128.3","93.157.139.115","146.19.125.36","152.236.4.14","77.110.125.143","172.86.90.75","89.106.83.49","45.32.186.198","157.173.29.133","45.61.134.62","104.194.134.167","68.210.224.231","144.172.95.50","45.142.31.17","172.86.113.245","217.69.8.54","167.88.167.37","93.157.139.123")

    Detection Query 3 :

    sha256hash IN ("a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe")

    Detection Query 4 :

    datasourcename = "Windows Security" and eventtype = "4663" and objectname In ("!!!README!!!DO_NOT_DELETE.txt")

    Detection Query 5 :

    technologygroup = "EDR" and objectname In ("!!!README!!!DO_NiOT_DELETE.txt") 

    Reference: 

    https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation           

     


    Tags

    Threat ActorRansomwareExploitationAICredential HarvestingDCSyncMS-SQLExfiltrationCloud InfrastructureLinux

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags