Ransomware Operators Are Using AI Coding Agents Now
Aurora used Cursor AI agent to write exploits against ESXi hypervisors. Anthropic's September 2026 report described seven categories of AI abuse, including autonomous cyber operations: Russian agents evaded antivirus for 130 days in 24 Ukrainian institutions, Chinese agents found over a dozen zero-days in a month.
- Aurora delegated Cursor to analyze vulnerabilities and deliver exploits to ESXi
- AI agents breached a corporate network in 10 hours versus days for humans
- Russian agents autonomously evaded detection for 130 days in 24 Ukrainian institutions
- One operator processed 1.8 million Android APKs via 10 AWS workers
Read next
Security