An exposed server belonging to an Aurora ransomware affiliate has revealed months of attack activity against more than 20 organisations across nine countries, giving researchers an unusually detailed view of how a ransomware operator moves from network compromise to data theft, encryption, extortion and payment laundering.
The exposed directory contained the operator’s Linux home directory, shell history, credential material, attack tooling, victim data, AI-assisted planning sessions and the Aurora ransomware encryptor itself, a CloudSEK investigation has revealed.
Working with TRM Labs, CloudSEK also traced a ransom payment on-chain. TRM Labs’ wider analysis identified two confirmed victim payments and two additional payments consistent with separate victims, with the funds ultimately converging through shared laundering infrastructure.
The findings provide a rare attacker-side view of a ransomware operation, showing not only the tools and techniques used to compromise organisations but also how the attacker planned intrusions, deployed ransomware and handled the financial proceeds.
20+ organisations compromised, 17 reached at domain or interactive level
The operator was active across the exposed dataset between April and July 2026 and compromised more than 20 organisations in nine countries.
CloudSEK found that the attacker achieved domain-level or interactive access at 17 organisations. Four of the organisations recorded in the attacker’s files were subsequently listed on Aurora’s public leak site, connecting the activity observed inside the operator’s infrastructure with later public extortion.
The victim set covered multiple industries, including manufacturing and industrial organisations, food and agriculture, professional and financial services, transport and logistics, consumer goods, environmental services, and IT and backup infrastructure. The United States accounted for the largest share of confirmed victims.
In several cases, the attacker obtained highly privileged access or sensitive material, including domain administrator credentials, Kerberos tickets, VPN credentials, Group Policy information, backup-system credentials and other authentication data.
Most of the affected organisations identified in the dataset have not appeared on public ransomware leak sites. CloudSEK initiated coordinated notification with relevant national CERTs and/or affected organisations before publication for victims that had not already been publicly identified.
AI coding assistant used to plan real-world attacks
One of the most significant findings was the operator’s use of Cursor, an AI-powered coding assistant, during attack planning.
Recovered sessions showed the attacker using Cursor in Russian to reason through attack sequences, including detailed planning around Active Directory Certificate Services exploitation. The chat history showed sustained back-and-forth use of the AI tool during victim engagements.
The finding offers direct visibility into how readily available AI tools are being incorporated into cybercriminal workflows, not merely for generating code, but for planning and working through attack paths against enterprise environments.
A repeatable playbook for compromising enterprise networks
The exposed directory allowed CloudSEK researchers to reconstruct a repeatable attack methodology used across multiple targets.
The operator repeatedly performed Active Directory and SMB discovery, retrieved password policies and carried out Kerberoasting and AS-REP Roasting. For privilege escalation, the attacker relied on several techniques depending on the environment, including a custom noPac chain, Active Directory Certificate Services abuse across ESC1, ESC6 and ESC8, and NTLM relay attacks using PetitPotam, PrinterBug and DFSCoerce.
Exploit code for at least a dozen vulnerabilities was also stored in the exposed environment. Much of it consisted of public proof-of-concept code, while some tooling had been modified and a FortiOS toolkit had been rebuilt as an independent framework.
The operator maintained custom NetExec modules, including tools designed to collect browser credentials across multiple browsers and identify ESXi infrastructure.
CloudSEK assesses with high confidence that the individual was operating directly as an Aurora ransomware affiliate rather than functioning solely as an initial-access broker. The activity continued beyond obtaining access into credential theft, domain compromise, exfiltration, ransomware staging and extortion.
Aurora ransomware built in Zig targets Windows, Linux and ESXi
The exposed environment also contained multiple versions of the Aurora encryptor for Windows and Linux/ESXi systems.
Both versions were written in Zig, a relatively uncommon programming language in ransomware development. The Windows and Linux variants appear to have been built from the same Zig codebase and compiled for different operating systems.
The encryptor supports several options designed to speed up or customise encryption, including partial-file encryption, multithreading and file-size restrictions.
The Linux/ESXi version contains functionality specifically designed for virtual infrastructure. Before encryption begins, the ransomware enumerates running virtual machines and force-terminates them. It also handles ransom-note delivery differently: instead of simply dropping a note as a file, it can modify the ESXi host’s SSH login banner so that the ransom message appears when administrators connect to the server.
The report includes indicators of compromise and a detection rule designed to identify this behaviour.
Following the ransom payment trail
The exposed files also provided researchers with visibility into the financial side of the operation. The wallet address the operator provided for payment was found to hold 7 BTC at the time of analysis, a balance more consistent with accumulated proceeds from several victims than a single payment, and itself a strong indicator that this operator’s activity generates significant revenue.
A key recovered from the Aurora encryptor allowed CloudSEK to access records from a completed ransom negotiation. The victim involved is not being named.
Working with TRM Labs, CloudSEK traced the resulting payment on-chain and examined how the funds moved after payment.
The wider analysis identified two confirmed victim payments and two additional payments consistent with separate victims. While each payment began on a separate path, several later converged at shared consolidation points before moving towards cash-out infrastructure.
Researchers also observed differing splits across the payments analysed, including 35/65, 21/79, 46/54 and 40/60, with no single ratio consistently repeated. The finding suggests that, across the transactions examined, the division of proceeds between participants was not based on a single fixed percentage.
Most of the traced funds passed through two dominant consolidation clusters before reaching cash-out addresses. One payment followed a different route through a peeling chain, where funds were gradually moved across a sequence of transactions rather than through the main consolidation hubs.
The financial activity observed in the investigation suggests that Aurora-linked ransomware activity may extend beyond the victims visible on public leak sites.
Russian-speaking operator, CIS targets absent from observed dataset
CloudSEK assesses with high confidence that the operator is Russian-speaking.
The assessment is based on material created directly by the attacker, including Cursor conversations, module documentation and session notes written in Russian.
Researchers also found that no CIS-allocated IP ranges or CIS-country domains appeared in three months of the operator’s target lists, scans or success logs.
CloudSEK’s assessment relates to the operator’s language and the targeting behaviour visible in the recovered dataset and does not establish the individual’s nationality or physical location.
Why the investigation matters
Ransomware investigations typically begin after an organisation has already been compromised, forcing defenders and researchers to reconstruct an attack from the victim’s environment.
In this case, the exposed directory provided visibility from the other side.
Researchers were able to examine the attacker’s working environment, understand how organisations were enumerated, follow privilege-escalation attempts, review stolen credentials and attack tools, observe the use of AI during operational planning, analyse the ransomware itself and follow a victim payment into cryptocurrency laundering infrastructure.
Taken together, the findings provide an unusually detailed picture of the operational lifecycle of a modern ransomware affiliate, from enterprise intrusion and data theft to encryption, extortion and the movement of ransom proceeds.
The full report also includes technical indicators of compromise, attacker infrastructure, malware hashes, detection rules and detailed mitigation recommendations to help organisations identify and defend against similar activity.
Middle East ransomware activity surges over 20X as hacktivism, state-linked espionage and AI-assisted threats converge: CloudSEK
Posted in Commentary with tags CloudSEK on September 16, 2026 by itnerdRansomware activity targeting the Middle East surged to its highest level during the 17-month period assessed by CloudSEK, jumping from 17 threat intelligence feeds in April 2025 to 357 in June 2026 — more than a 20-fold increase.
The sharp ransomware escalation is part of a wider shift in the region’s cyber threat landscape, where financially motivated cybercrime is increasingly operating alongside politically driven hacktivism, state-linked espionage, destructive attacks and rapid exploitation of critical vulnerabilities.
CloudSEK’s new Middle East Cyber Threat Landscape 2025–2026 analyses threat activity across ransomware, hacktivism, dark web sources, adversary intelligence, malware and vulnerability intelligence between April 2025 and August 31, 2026. The report recorded its highest overall monthly volume in March 2026, with 2,245 threat intelligence feeds, while Israel was the most targeted country overall with 7,112 feeds.
The findings point to what CloudSEK describes as an increasingly “structurally complex” threat environment, in which organisations must defend simultaneously against high-volume disruptive attacks, financially motivated ransomware and quieter, longer-dwell espionage operations.
Key findings from the report
Ransomware shifts the regional threat equation
One of the report’s most significant findings is the divergence between hacktivism and ransomware.
Hacktivist activity dominated much of 2025 and surged during periods of geopolitical escalation, particularly in June 2025, October 2025 and March 2026. From April 2026 onwards, however, hacktivist volumes declined sharply.
Ransomware moved in the opposite direction. Its slower but sustained rise culminated in the June 2026 spike, at precisely the period when hacktivist activity was falling most sharply. CloudSEK’s analysis suggests that politically motivated hacktivists and financially motivated ransomware operators largely operate according to different cycles rather than competing for the same attack windows.
Nova emerged as the most prolific ransomware operator identified in the regional dataset, while groups including The Gentlemen, Qilin, LockBit5 and DragonForce also appeared in campaigns affecting Middle Eastern organisations. The report highlights The Gentlemen as an emerging ransomware operator that exploited the Fortinet authentication-bypass vulnerability CVE-2024-55591, alongside VPN credential brute-forcing and the use of Rclone for data theft.
Asset-heavy industries are becoming particularly attractive because disruption can translate directly into operational and financial pressure. Facility management, industrial operations, property management, infrastructure and manufacturing were among the most targeted ransomware sectors.
Geopolitics continues to reshape cyber operations
Hacktivism remained the single largest threat category by volume across the reporting period. Israel was overwhelmingly its primary target, accounting for 37.8% of regional hacktivist activity, followed by Iran. Groups tracked during the period included SKYNET, HeziRash, DieNet, Keymous, OpIsrael, DARKSTORM, NoName057(16) and Handala.
The report also documents a shift in the geographic scope of some actors. Handala, historically focused heavily on Israeli organisations, was recorded targeting UAE critical infrastructure in April 2026, indicating that cyber operations associated with regional geopolitical tensions were extending beyond their traditional target sets.
At the same time, the region continued to face sophisticated espionage activity involving Iranian-linked actors including MuddyWater, Charming Kitten/APT35, APT42, Nimbus Manticore and OilRig, alongside other state-linked and advanced operators.
AI moves into the offensive cyber toolkit
An emerging development identified by CloudSEK is the use of generative AI to support offensive cyber operations.
The report documents MuddyWater using Google’s Gemini AI model to obfuscate PowerShell code, potentially making static analysis of malicious payloads more difficult. It also identifies evidence of AI-assisted malware development by Nimbus Manticore/UNC1549, which CloudSEK says could help accelerate tooling adaptation and operational tempo.
Nimbus Manticore also expanded operations across aviation, defence, telecommunications, software development and government targets, employing phishing, trojanised software installers, SEO poisoning and its MiniFast and MiniJunk malware tooling.
This signals a shift from AI being primarily discussed as a future offensive capability to its emerging use within the workflows of active threat actors.
UAE and Saudi Arabia face growing ransomware and espionage pressure
The UAE recorded 2,588 overall activity indicators and faced activity ranging from ransomware and dark-web exposure to state-linked campaigns.
CloudSEK documented MuddyWater campaigns targeting UAE maritime and industrial organisations, including region-specific phishing lures and a multi-stage Remcos RAT delivery chain. The actor also evolved its tooling toward the Rust-based RustyWater implant, reflecting continued investment in detection evasion.
Saudi Arabia, meanwhile, recorded 1,880 overall activity indicators and saw sustained interest from ransomware operators and underground cybercriminal markets. The Gentlemen targeted Saudi organisations during the reporting period, while Nimbus Manticore identified Saudi Arabia among the regions affected by its expanded operations.
CloudSEK currently assesses organisations in UAE and Saudi critical infrastructure as among the highest-risk groups in the region, alongside Israeli government, defence and healthcare organisations and Turkish industrial and manufacturing companies.
Dark web markets are monetising enterprise access
The report also points to sustained underground demand for credentials, corporate data and access to Middle Eastern enterprise systems.
Financial services and government organisations featured prominently in dark-web activity, alongside e-commerce, banking, investment, retail, education and telecommunications targets. CloudSEK observed significant credential theft, initial-access broker listings and leaked corporate information linked to Gulf organisations.
One campaign involving threat actor xpl0itrs, linked to TeamPCP, involved the sale of unauthorised access to Salesforce Experience Cloud environments belonging to government and financial-services targets. Prices ranged from $2,000 to $40,000 per victim. CloudSEK notes that the activity exploited misconfigured Guest User permissions rather than a previously unknown zero-day.
Critical vulnerabilities continue to provide attackers a path inside
Network-edge infrastructure — particularly VPNs, firewalls and SSL gateways — remained one of the most important initial-access vectors during the reporting period.
CloudSEK highlights actively exploited vulnerabilities affecting Fortinet FortiOS/FortiProxy, Ivanti Connect Secure and Microsoft Windows, while critical vulnerabilities in React Server Components, Kubernetes ingress-nginx, Erlang/OTP and Apache Parquet expanded the potential attack surface for cloud-first and digitally transforming organisations.
The nine major vulnerabilities assessed in the report had an average CVSS score of 9.2, placing all of them within Critical or High severity bands.
CloudSEK recommends organisations urgently patch exposed network-edge and web infrastructure, harden Salesforce and API permissions, strengthen phishing-resistant authentication, segment operational technology networks, maintain immutable offline backups, and test DDoS and incident-response capabilities.
Lower hacktivist noise should not be mistaken for lower cyber risk
Despite a decline in hacktivism after March 2026, CloudSEK warns organisations against interpreting reduced public-facing cyber disruption as an improvement in the overall threat environment.
Ransomware continued at elevated levels while state-linked actors evolved their tooling and techniques. CloudSEK consequently assesses the Middle East’s immediate post-reporting cyber threat environment as ELEVATED-HIGH.
For More Information, Read The Full Report
Leave a comment »