An exposed directory revealed extensive Aurora ransomware operations by a Russian-speaking affiliate active against over twenty organisations between April and July 2026. The misconfigured server exposed the operator's complete toolkit, shell history, AI-assisted attack planning via Cursor, and the Aurora encryptor written in Zig. CloudSEK recovered keys enabling visibility into ransom negotiations and traced payments on-chain in partnership with TRM Labs, identifying connections between multiple victims through shared laundering infrastructure. The operator demonstrated sophisticated capabilities including Active Directory compromise, ADCS exploitation, and ESXi targeting, while consistently excluding CIS ranges and domains. Four victims have appeared on Aurora's leak site, though financial analysis suggests broader impact with varied affiliate payment splits.
Created: 2026-08-27
類似するPulseは見つかりませんでした。
このPulseに見つかったCVEはありません。