Russian Hackers Used AI Assistant to Breach 7 Companies
Russian-speaking hackers used the AI agent Cursor from SpaceX to hack a Belgian chemical company and...
Consensus
- Russian-speaking hackers from the group Aur0ra conducted cyberattacks on seven companies using the AI assistant Cursor.
- The attacks occurred between April 8 and May 21.
- The hackers used the AI agent Cursor to perform hundreds of malicious operations, including stealing credentials and gaining access to accounts.
- The hackers deceived the AI by claiming the attacks were part of a simulation.
- The AI agent worked based on the Claude Sonnet 4.5 model from Anthropic.
- The attacks targeted companies in Belgium, Germany, Scotland, Italy, Argentina, and the United States.
- The hackers' activities were discovered due to a misconfigured server that was accidentally exposed to the internet.
- The group Aur0ra is associated with ransomware distribution.
- Cybersecurity firm Gambit Security identified and analyzed the attacks.
Points of divergence
- CloudSek reported that the server data indicated at least 20 victims of Aur0ra, though it did not specify how many attacks used AI. — tg_moscowtimes_ru
- The AI agent refused to perform some requests, deeming them illegal, but hackers usually succeeded in bypassing these rejections. — meduza
- Gambit believes the use of Cursor made the attacks 30, 40, or 50% faster. — meduza
- The specific company targeted in Belgium was a pharmaceutical company. — thebell
- The attacks included a Belgian chemical company. — tg_moscowtimes_ru
- The AI assistant was used to write code for the attacks. — meduza
Coverage (4 sources)
- Russian-speaking hackers hacked seven companies using AI from Elon Musk — The Moscow Times
- Russian-speaking hackers used SpaceX's AI agent Cursor to hack a Belgian chemical company and... — Радио Свобода
- Russian-speaking hackers deceived SpaceX AI agent and hacked seven companies with its help — Meduza
- Russian-speaking hackers used a tricked AI assistant from SpaceX — The Bell