A Russian-speaking hacking group used the AI coding assistant Cursor to help break into at least seven companies, highlighting how artificial intelligence is moving beyond software development and becoming a powerful tool for cybercriminals.
A new investigation has uncovered one of the clearest examples yet of how artificial intelligence can be abused during real-world cyberattacks.
According to data reviewed by Reuters and reports from cybersecurity firms Gambit Security and CloudSek, a new ransomware group known as Aur0ra used Cursor to carry out hundreds of malicious operations during attacks against companies in several countries.
The identified victims include a Belgian hygiene-products company, a German garage-door manufacturer, a Scottish helicopter certification agency, an Argentine pharmaceutical distributor, an Italian manufacturer and a U.S. title-insurance company.
How Was the Operation Discovered?
Gambit Security investigators discovered the campaign after finding an internet-exposed server belonging to the Aur0ra group.
The server contained 28 chat sessions between hackers and a Cursor AI agent, covering activity between April 8 and May 21.
The conversations gave researchers a rare look into how cybercriminals are using AI during active intrusions.
According to Gambit, the hackers convinced the AI agent that the activity was part of a security simulation.
That allowed the system to continue with tasks it would normally have refused.
AI Was Used for Hundreds of Operations

The attackers did not use AI simply to search for information.
They used the agent for operational tasks.
According to investigators, those included:
- searching for and stealing credentials;
- taking over privileged accounts;
- analyzing victims’ systems;
- identifying vulnerabilities;
- helping exploit exposed systems;
- and automating parts of the attack process.
In one case, after identifying a vulnerable host inside a German company’s network, the agent recommended using a known malicious tool to exploit the weakness.
The Hackers Tricked the AI
This may be the most concerning part of the story.
Cursor did not always accept the hackers’ requests.
In several cases, the system refused to assist with harmful activity.
But the attackers found a way around the restrictions.
They restarted conversations and claimed that the activity was part of an authorized security test.
According to Gambit, the tactic worked often enough for the agent to continue providing technical assistance.
The case exposes a major problem for modern AI systems:
A model can have safety controls, but malicious users can repeatedly attempt to manipulate those controls.
How Much Faster Did AI Make the Hackers?
Gambit researchers estimated that the AI assistant may have helped the attackers work 30% to 50% faster during some parts of the operation.
That does not mean AI carried out the attacks independently.
Reuters noted that it could not independently determine exactly how much the Cursor agent contributed to each intrusion or whether every breach resulted in data theft or extortion.
But even a productivity increase of several dozen percent can be significant.
In a traditional attack, hackers may spend hours or days researching documentation, analyzing systems and writing or adapting code.
An AI agent can accelerate some of those steps dramatically.
Aur0ra Is Believed to Have Claimed at Least 20 Victims

CloudSek said data found on the exposed server suggested that Aur0ra had claimed at least 20 victims.
However, it remains unclear how many were actually compromised with AI assistance.
Reuters independently identified six companies by examining portions of the data.
The victims span multiple industries.
That is what makes the case particularly concerning.
AI-assisted attacks are not limited to a single type of organization.
The New Problem: AI vs. AI
The incident illustrates a new reality in cybersecurity.
Companies are using AI for:
- threat detection;
- malware analysis;
- network defense;
- incident response;
- and security automation.
Attackers are using the same technology for:
- attack automation;
- vulnerability research;
- tool development;
- network analysis;
- and operational acceleration.
That creates a new technological arms race, with defenders and attackers increasingly using AI against each other.
This Is Not an Isolated Incident

The discovery comes as concern about AI-assisted cyberattacks is accelerating.
Just one day earlier, more than 100 major technology, financial and cybersecurity companies — including OpenAI, Anthropic, Microsoft, Google, Amazon and CrowdStrike — called for a broader response to the growing threat of AI-powered cyberattacks.
In a joint letter, the companies warned that AI-enabled attacks could become significantly more widespread and sophisticated in the coming months.
The Aur0ra campaign therefore does not look like an isolated event.
It is part of a broader shift in how cybersecurity is evolving.
What Happens Next?
AI companies face an increasingly difficult question:
How do you make an AI agent useful enough for legitimate professionals without turning it into a weapon for criminals?
The Tech Spot Editorial Team
If safeguards are too restrictive, legitimate users may lose much of the technology’s value.
If they are too weak, attackers may find ways to turn AI into an accelerator for cyberattacks.
That problem cannot be solved simply by adding another filter.
It will require continuous monitoring, testing, cooperation between AI developers and security researchers, and potentially new regulatory frameworks.
TheTechSpot: Hackers No Longer Need to Be Experts at Everything
For years, one of the biggest barriers to launching a sophisticated cyberattack was technical knowledge.
Attackers needed to understand networking.
They needed scripting skills.
They needed knowledge of operating systems.
They needed to know how to identify and exploit vulnerabilities.
AI is lowering that barrier.
That does not mean anyone can instantly become a professional hacker.
But it does mean that an attacker with limited knowledge can receive technical assistance in real time and move much faster.
And that may be the biggest change AI is bringing to cybersecurity.
The danger is not simply that AI can make attacks more powerful.
It is that AI can make some attacks faster, cheaper and more accessible.
The next cybersecurity arms race may no longer be simply hacker versus security expert.
It could increasingly become:
AI versus AI.