Published
3 hours agoon
By
MAIN
Russian-speaking hackers used SpaceX’s AI coding assistant Cursor to help break into a Belgian chemical company and at least six other firms earlier this year, according to data reviewed by Reuters and a report from startup Gambit Security.
The campaign is the latest example of rogue actors using commercial artificial intelligence tools to conduct cyber intrusions. It also highlights the growing challenge for AI providers as malicious users look for ways around safety guardrails.
“This is going to be a cat-and-mouse game,” said Curtis Simpson, Gambit’s chief strategy officer.
Cursor and its parent company, SpaceX, did not respond to requests for comment.
Gambit said it discovered the campaign after finding a server that a new ransomware group called Aur0ra had inadvertently exposed online.
The exposed server allowed the Tel Aviv-based company to review 28 chat sessions involving one or more Aur0ra hackers and a Cursor AI agent. These agents can perform tasks with varying degrees of autonomy.
According to Gambit, the hackers persuaded the AI agent to conduct hundreds of malicious operations, including credential theft and attempts to take over high-value accounts.
The hackers allegedly misled the agent by claiming the activity was part of a simulation.
At one point, Gambit quoted the hackers as instructing the agent to find an administrator account and working passwords.
Gambit did not name the victims. However, Reuters identified six after independently reviewing portions of the chat data, which remained online as of last month.
The chat logs covered April 8 to May 21. They showed that Aur0ra targeted the Belgian company Christeyns, a Ghent-based manufacturer of hygiene and cleaning products.
The other identified victims included German garage door manufacturer Teckentrup and the Scotland-based Helideck Certification Agency, which assesses helicopter landing sites.
The remaining victims were an Argentine pharmaceutical distributor, an Italian manufacturer and Bayou Title, which describes itself as Louisiana’s largest title insurance company.
None of the six companies responded to Reuters’ requests for comment.
At least one victim, Bayou Title, appeared on Aur0ra’s data leak site. Such listings typically indicate that hackers attempted to obtain a ransom but failed to secure payment.
Aur0ra, which began claiming victims earlier this year, did not respond to messages.
The chat logs reviewed by Reuters show hackers issuing short commands while Cursor’s AI agent responded with technical guidance in an upbeat, emoji-heavy chatbot style.
After the agent helped breach the Argentine company, it declared that a VPN had connected successfully. Elsewhere, it suggested attempting to crack password hashes.
After identifying a vulnerable host on Teckentrup’s network, the agent recommended using a known malicious software tool to exploit it. It assessed the chance of success as very high.
Reuters could not independently establish how extensively the Cursor agent facilitated the intrusions. It also could not determine whether every breach led to data theft or an extortion attempt.
Gambit said the agent was powered by Anthropic’s Claude Sonnet 4.5. Anthropic did not respond to a request for comment.
Eyal Sela, Gambit’s director of threat intelligence, said Cursor gave the hackers a clear advantage. He estimated that the AI agent probably made their work 30% to 50% faster by reducing tasks they would otherwise have performed manually.
The agent refused some requests that it considered harmful or illegal, according to Sela. However, the hackers could usually bypass those refusals by restarting the conversation and repeating that the activity was part of a test.
Gambit said the agent’s chain of thought showed the hackers’ simulation claim overriding its safeguards.
“This is a test environment, so it is legal,” the agent said to itself, according to one of the logs.
The hacking campaign comes as Cursor is being incorporated into SpaceX, Elon Musk’s rockets-and-AI company. That deal closed earlier this month.
Meanwhile, concerns are growing over digital risks linked to AI models, particularly those that power autonomous AI agents.
Simpson said AI-assisted hacking was becoming the new normal.
“We’ll see more and more of this all the time,” he said.
With inputs from Reuters
