Guest Post: Exposed Server Reveals Aurora Ransomware Affiliate’s Attacks on 20+ Organisations, AI-Assisted Planning and Crypto Trail

An exposed server belonging to an Aurora ransomware affiliate has revealed months of attack activity against more than 20 organisations across nine countries, giving researchers an unusually detailed view of how a ransomware operator moves from network compromise to data theft, encryption, extortion and payment laundering.

The exposed directory contained the operator’s Linux home directory, shell history, credential material, attack tooling, victim data, AI-assisted planning sessions and the Aurora ransomware encryptor itself, a CloudSEK investigation has revealed.

Working with TRM Labs, CloudSEK also traced a ransom payment on-chain. TRM Labs’ wider analysis identified two confirmed victim payments and two additional payments consistent with separate victims, with the funds ultimately converging through shared laundering infrastructure.

The findings provide a rare attacker-side view of a ransomware operation, showing not only the tools and techniques used to compromise organisations but also how the attacker planned intrusions, deployed ransomware and handled the financial proceeds.

20+ organisations compromised, 17 reached at domain or interactive level

The operator was active across the exposed dataset between April and July 2026 and compromised more than 20 organisations in nine countries.

CloudSEK found that the attacker achieved domain-level or interactive access at 17 organisations. Four of the organisations recorded in the attacker’s files were subsequently listed on Aurora’s public leak site, connecting the activity observed inside the operator’s infrastructure with later public extortion.

The victim set covered multiple industries, including manufacturing and industrial organisations, food and agriculture, professional and financial services, transport and logistics, consumer goods, environmental services, and IT and backup infrastructure. The United States accounted for the largest share of confirmed victims.

In several cases, the attacker obtained highly privileged access or sensitive material, including domain administrator credentials, Kerberos tickets, VPN credentials, Group Policy information, backup-system credentials and other authentication data.

Most of the affected organisations identified in the dataset have not appeared on public ransomware leak sites. CloudSEK initiated coordinated notification with relevant national CERTs and/or affected organisations before publication for victims that had not already been publicly identified.

AI coding assistant used to plan real-world attacks

One of the most significant findings was the operator’s use of Cursor, an AI-powered coding assistant, during attack planning.

Recovered sessions showed the attacker using Cursor in Russian to reason through attack sequences, including detailed planning around Active Directory Certificate Services exploitation. The chat history showed sustained back-and-forth use of the AI tool during victim engagements.

The finding offers direct visibility into how readily available AI tools are being incorporated into cybercriminal workflows, not merely for generating code, but for planning and working through attack paths against enterprise environments.

A repeatable playbook for compromising enterprise networks

The exposed directory allowed CloudSEK researchers to reconstruct a repeatable attack methodology used across multiple targets.

The operator repeatedly performed Active Directory and SMB discovery, retrieved password policies and carried out Kerberoasting and AS-REP Roasting. For privilege escalation, the attacker relied on several techniques depending on the environment, including a custom noPac chain, Active Directory Certificate Services abuse across ESC1, ESC6 and ESC8, and NTLM relay attacks using PetitPotam, PrinterBug and DFSCoerce.

Exploit code for at least a dozen vulnerabilities was also stored in the exposed environment. Much of it consisted of public proof-of-concept code, while some tooling had been modified and a FortiOS toolkit had been rebuilt as an independent framework.

The operator maintained custom NetExec modules, including tools designed to collect browser credentials across multiple browsers and identify ESXi infrastructure.

CloudSEK assesses with high confidence that the individual was operating directly as an Aurora ransomware affiliate rather than functioning solely as an initial-access broker. The activity continued beyond obtaining access into credential theft, domain compromise, exfiltration, ransomware staging and extortion.

Aurora ransomware built in Zig targets Windows, Linux and ESXi

The exposed environment also contained multiple versions of the Aurora encryptor for Windows and Linux/ESXi systems.

Both versions were written in Zig, a relatively uncommon programming language in ransomware development. The Windows and Linux variants appear to have been built from the same Zig codebase and compiled for different operating systems.

The encryptor supports several options designed to speed up or customise encryption, including partial-file encryption, multithreading and file-size restrictions.

The Linux/ESXi version contains functionality specifically designed for virtual infrastructure. Before encryption begins, the ransomware enumerates running virtual machines and force-terminates them. It also handles ransom-note delivery differently: instead of simply dropping a note as a file, it can modify the ESXi host’s SSH login banner so that the ransom message appears when administrators connect to the server.

The report includes indicators of compromise and a detection rule designed to identify this behaviour.

Following the ransom payment trail

The exposed files also provided researchers with visibility into the financial side of the operation. The wallet address the operator provided for payment was found to hold 7 BTC at the time of analysis, a balance more consistent with accumulated proceeds from several victims than a single payment, and itself a strong indicator that this operator’s activity generates significant revenue.

A key recovered from the Aurora encryptor allowed CloudSEK to access records from a completed ransom negotiation. The victim involved is not being named.

Working with TRM Labs, CloudSEK traced the resulting payment on-chain and examined how the funds moved after payment.

The wider analysis identified two confirmed victim payments and two additional payments consistent with separate victims. While each payment began on a separate path, several later converged at shared consolidation points before moving towards cash-out infrastructure.

Researchers also observed differing splits across the payments analysed, including 35/65, 21/79, 46/54 and 40/60, with no single ratio consistently repeated. The finding suggests that, across the transactions examined, the division of proceeds between participants was not based on a single fixed percentage.

Most of the traced funds passed through two dominant consolidation clusters before reaching cash-out addresses. One payment followed a different route through a peeling chain, where funds were gradually moved across a sequence of transactions rather than through the main consolidation hubs.

The financial activity observed in the investigation suggests that Aurora-linked ransomware activity may extend beyond the victims visible on public leak sites. 

Russian-speaking operator, CIS targets absent from observed dataset

CloudSEK assesses with high confidence that the operator is Russian-speaking.

The assessment is based on material created directly by the attacker, including Cursor conversations, module documentation and session notes written in Russian.

Researchers also found that no CIS-allocated IP ranges or CIS-country domains appeared in three months of the operator’s target lists, scans or success logs.

CloudSEK’s assessment relates to the operator’s language and the targeting behaviour visible in the recovered dataset and does not establish the individual’s nationality or physical location.

Why the investigation matters

Ransomware investigations typically begin after an organisation has already been compromised, forcing defenders and researchers to reconstruct an attack from the victim’s environment.

In this case, the exposed directory provided visibility from the other side.

Researchers were able to examine the attacker’s working environment, understand how organisations were enumerated, follow privilege-escalation attempts, review stolen credentials and attack tools, observe the use of AI during operational planning, analyse the ransomware itself and follow a victim payment into cryptocurrency laundering infrastructure.

Taken together, the findings provide an unusually detailed picture of the operational lifecycle of a modern ransomware affiliate, from enterprise intrusion and data theft to encryption, extortion and the movement of ransom proceeds.

The full report also includes technical indicators of compromise, attacker infrastructure, malware hashes, detection rules and detailed mitigation recommendations to help organisations identify and defend against similar activity.

For more information, read the full report.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading