Russian-speaking hackers used AI in cyberattacks on companies in the US and Europe
/ 28 August 2026 08:48
3 min to read
The Russian-speaking hacking group Aur0ra used an AI assistant to program Cursor during cyberattacks on companies in Europe and the United States. Cybersecurity researchers have found that the attackers managed to convince the artificial intelligence to perform malicious operations, presenting real attacks as legitimate testing of security systems. According to various estimates, the group’s victims ranged from seven to at least 20 organizations.
This was reported by Reuters, citing research by cybersecurity companies Gambit Security and CloudSek.
The hacking campaign was investigated in detail after the attackers themselves made a mistake. Gambit analysts discovered the Aur0ra server, which the group accidentally left open on the network.
Thanks to this, experts gained access to information about 28 sessions of interaction between the hackers and the AI agent.
Hackers convinced AI that they were conducting “testing”
According to the researchers, Aur0ra used AI to perform hundreds of operations as part of the attacks. Among them were stealing credentials and gaining control of valuable accounts.
At the same time, the system did not always agree to execute commands.
The AI agent repeatedly rejected requests that it identified as potentially malicious or illegal. However, the hackers restarted the dialogue and convinced the system that they were working in a test environment and were supposedly conducting an authorized security check.
As a result, the agent accepted the context set by the attackers and continued to perform the tasks, the study found.
AI could speed up attacks by 30-50%
Gambit Director of Threat Analysis Eyal Sela believes that the use of AI has significantly increased the speed of hackers’ work.
According to his assessment, the AI agent could help attackers act 30-50% faster, as it automated some of the processes that would normally have to be performed manually.
Gambit warns that the confrontation between AI developers and cybercriminals could turn into a constant technological race: companies will install new protective mechanisms, and attackers will look for ways to bypass them.
Among the victims are companies in Europe and the United States
The researchers analyzed chat logs for the period from April 8 to May 21.
Among the organizations mentioned as victims of the attacks are Belgian detergent manufacturer Christeyns, German garage door manufacturer Teckentrup, and the Scottish Helipad Certification Agency.
The attacks also affected organizations in Argentina, Italy, and the United States.
According to CloudSek, the total number of organizations affected by Aur0ra’s activities may be at least 20.
AI becomes a new tool for cybercriminals
The discovered campaign demonstrates a new risk for cybersecurity: AI agents can not only help programmers perform routine tasks, but also accelerate certain stages of cyberattacks if attackers manage to bypass the established restrictions.
At the same time, the scheme described by the researchers shows that AI defense mechanisms still reacted to some of the dangerous commands. The problem was that hackers were able to change the context of requests and pass off a real attack as authorized testing.
This creates a new challenge for companies: cybercriminals have tools that can automate some of the work and potentially reduce the time required to carry out attacks.
Without an author