Researchers tied to the Aurora ransomware group described a real intrusion that started with aggressive email bombing, then phone calls where attackers posed as the IT help desk to “help” employees fix the issue. Separate reporting shows the same group used the Cursor AI coding assistant to plan and guide hands-on exploitation once they already had credentials or a way into victim networks.
How the Attack Worked
A documented Aurora ransomware intrusion began not with a phishing email but with disruption. Attackers flooded an employee's inbox with an aggressive email bomb, creating a stressful and urgent situation. Shortly after, a phone call followed from someone claiming to be IT help desk staff, offering to help resolve the email flood. That offer of help was the actual attack: following the caller's instructions led to remote access being established using an open-source utility called Xray-core.
Separate reporting from CloudSEK and Gambit Security describes Aurora operators also using the Cursor AI coding assistant once they already had credentials or an existing route into a victim's network. The AI agent was reportedly tasked with hands-on activities including VPN and proxy setup, scanning internal subnets with tools like Nmap or NetExec, domain privilege enumeration, NTLM relay attempts, and certificate-based attacks.
Why It Succeeded
The email bombing created a moment of genuine technical disruption and stress. When a caller then appeared to offer a fix, framed as internal IT support, employees were primed to accept help rather than question it. The pretext exploited the natural instinct to resolve an active problem quickly, and the caller's offer to "fix" the issue provided a plausible reason to follow instructions that led to remote access being enabled.
Once inside, the reported use of an AI coding assistant to guide exploitation suggests attackers were able to move through scanning, enumeration, and privilege escalation steps efficiently after gaining that initial foothold.
What to Watch For
- Unsolicited help desk calls that arrive right after or during an unexplained email flood or inbox disruption
- Pressure to act quickly to stop a disruption, especially when it involves installing or enabling remote access software
- Requests to run tools or accept remote connections without a documented support ticket
- Unusual internal network scanning or enumeration activity following any unverified support interaction
Building Resistance
Organizations can reduce the risk of this pretext succeeding by reinforcing a few habits across all employees, not just technical staff:
- Verify any unexpected IT help desk contact using a known internal number or the official ticketing system, never a number or link provided by the caller
- Require an approved support process and documented ticket before installing or enabling any remote access tool
- Train IT operations and service desk staff to recognize that a sudden email bombing incident may be a precursor to a vishing based intrusion attempt, not just a nuisance
- Monitor for unusual internal scanning or enumeration behavior following any support interaction, since attackers may use automated or AI assisted tooling to move quickly once inside
The combination of a disruptive pretext with a helpful sounding follow up call is a pattern that can be rehearsed and recognized. Reinforcing verification habits around unsolicited IT contact remains one of the most direct ways to reduce the chance that this kind of pretext succeeds.
Key findings
- A documented Aurora intrusion used “aggressive email bombing” followed by phone calls impersonating the IT help desk to gain cooperation and establish remote access.
- CloudSEK and Gambit Security both report Aurora operators using Cursor (an AI coding assistant) to plan attacks and guide exploitation steps.
- Gambit Security observed Cursor Agent being used for hands-on tasks (VPN/proxy setup, internal scanning, domain privilege enumeration, NTLM relay attempts, and certificate attacks) once attackers had credentials or an existing access route.
- Victim names were not fully disclosed in the article; Reuters reportedly identified several affected organizations.
Who’s being targeted
- Commonly targeted roles: All employees, IT Helpdesk/Service Desk, IT Operations, Security Operations (SOC).
- Affected industries: Manufacturing, Professional services, Finance/Insurance, Healthcare/Pharmaceutical distribution.
- Attack channels: email, vishing.
- Impersonated: Internal IT help desk.
Red flags to watch for
- Unsolicited help desk calls tied to a sudden email flood
- Pressure to act quickly to stop the disruption
- Instructions that result in remote access being installed or enabled
Frequently asked questions
How did Aurora attackers gain initial access?
According to reporting, initial access was achieved via aggressive email bombing followed by phone calls where attackers posed as IT help desk personnel offering to help fix the issue, ultimately establishing remote access using an open-source utility called Xray-core.
What should employees do if they get an unexpected IT helpdesk call during an email flood?
Treat the call as suspicious and verify the caller's identity using known internal numbers or your organization's ticketing system before taking any action.
Did Aurora use AI tools in the attack?
Yes, separate reporting from CloudSEK and Gambit Security indicates Aurora operators used the Cursor AI coding assistant to plan attacks and guide hands-on exploitation once they had credentials or an existing route into a victim network.
What kind of exploitation activity was observed after initial access?
Gambit Security observed activity such as VPN/proxy setup, internal network scanning, domain privilege enumeration, NTLM relay attempts, and certificate attacks carried out with the help of an AI coding agent.
Read the video transcript
Imagine your inbox suddenly explodes with hundreds of emails… and then your phone rings. That’s how the Aurora ransomware gang got in: email bombing first, then a call, “Hi, this is IT help desk, we’re calling to help you deal with the email flood.” They walk you through steps that quietly install remote access, like Xray-core. Here’s the scary part: once Aurora had access, researchers saw them using an AI coding assistant called Cursor to script VPNs, scan internal systems, and hunt for domain privileges. The hard work is automated. If your inbox gets bombed and “IT help desk” calls out of the blue, hang up and call IT back using our official number or ticketing system before you do anything.