Aurora Gang Email-Bombs Staff, Poses as IT Helpdesk

The Hacker News · High sophistication
Last updated September 1, 2026

Researchers tied to the Aurora ransomware group described a real intrusion that started with aggressive email bombing, then phone calls where attackers posed as the IT help desk to “help” employees fix the issue. Separate reporting shows the same group used the Cursor AI coding assistant to plan and guide hands-on exploitation once they already had credentials or a way into victim networks.

How the Attack Worked

A documented Aurora ransomware intrusion began not with a phishing email but with disruption. Attackers flooded an employee's inbox with an aggressive email bomb, creating a stressful and urgent situation. Shortly after, a phone call followed from someone claiming to be IT help desk staff, offering to help resolve the email flood. That offer of help was the actual attack: following the caller's instructions led to remote access being established using an open-source utility called Xray-core.

Separate reporting from CloudSEK and Gambit Security describes Aurora operators also using the Cursor AI coding assistant once they already had credentials or an existing route into a victim's network. The AI agent was reportedly tasked with hands-on activities including VPN and proxy setup, scanning internal subnets with tools like Nmap or NetExec, domain privilege enumeration, NTLM relay attempts, and certificate-based attacks.

Why It Succeeded

The email bombing created a moment of genuine technical disruption and stress. When a caller then appeared to offer a fix, framed as internal IT support, employees were primed to accept help rather than question it. The pretext exploited the natural instinct to resolve an active problem quickly, and the caller's offer to "fix" the issue provided a plausible reason to follow instructions that led to remote access being enabled.

Once inside, the reported use of an AI coding assistant to guide exploitation suggests attackers were able to move through scanning, enumeration, and privilege escalation steps efficiently after gaining that initial foothold.

What to Watch For

  • Unsolicited help desk calls that arrive right after or during an unexplained email flood or inbox disruption
  • Pressure to act quickly to stop a disruption, especially when it involves installing or enabling remote access software
  • Requests to run tools or accept remote connections without a documented support ticket
  • Unusual internal network scanning or enumeration activity following any unverified support interaction

Building Resistance

Organizations can reduce the risk of this pretext succeeding by reinforcing a few habits across all employees, not just technical staff:

  • Verify any unexpected IT help desk contact using a known internal number or the official ticketing system, never a number or link provided by the caller
  • Require an approved support process and documented ticket before installing or enabling any remote access tool
  • Train IT operations and service desk staff to recognize that a sudden email bombing incident may be a precursor to a vishing based intrusion attempt, not just a nuisance
  • Monitor for unusual internal scanning or enumeration behavior following any support interaction, since attackers may use automated or AI assisted tooling to move quickly once inside

The combination of a disruptive pretext with a helpful sounding follow up call is a pattern that can be rehearsed and recognized. Reinforcing verification habits around unsolicited IT contact remains one of the most direct ways to reduce the chance that this kind of pretext succeeds.

Key findings

  • A documented Aurora intrusion used “aggressive email bombing” followed by phone calls impersonating the IT help desk to gain cooperation and establish remote access.
  • CloudSEK and Gambit Security both report Aurora operators using Cursor (an AI coding assistant) to plan attacks and guide exploitation steps.
  • Gambit Security observed Cursor Agent being used for hands-on tasks (VPN/proxy setup, internal scanning, domain privilege enumeration, NTLM relay attempts, and certificate attacks) once attackers had credentials or an existing access route.
  • Victim names were not fully disclosed in the article; Reuters reportedly identified several affected organizations.

Who’s being targeted

  • Commonly targeted roles: All employees, IT Helpdesk/Service Desk, IT Operations, Security Operations (SOC).
  • Affected industries: Manufacturing, Professional services, Finance/Insurance, Healthcare/Pharmaceutical distribution.
  • Attack channels: email, vishing.
  • Impersonated: Internal IT help desk.

Red flags to watch for

  • Unsolicited help desk calls tied to a sudden email flood
  • Pressure to act quickly to stop the disruption
  • Instructions that result in remote access being installed or enabled
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did Aurora attackers gain initial access?

According to reporting, initial access was achieved via aggressive email bombing followed by phone calls where attackers posed as IT help desk personnel offering to help fix the issue, ultimately establishing remote access using an open-source utility called Xray-core.

What should employees do if they get an unexpected IT helpdesk call during an email flood?

Treat the call as suspicious and verify the caller's identity using known internal numbers or your organization's ticketing system before taking any action.

Did Aurora use AI tools in the attack?

Yes, separate reporting from CloudSEK and Gambit Security indicates Aurora operators used the Cursor AI coding assistant to plan attacks and guide hands-on exploitation once they had credentials or an existing route into a victim network.

What kind of exploitation activity was observed after initial access?

Gambit Security observed activity such as VPN/proxy setup, internal network scanning, domain privilege enumeration, NTLM relay attempts, and certificate attacks carried out with the help of an AI coding agent.

Read the video transcript

Imagine your inbox suddenly explodes with hundreds of emails… and then your phone rings. That’s how the Aurora ransomware gang got in: email bombing first, then a call, “Hi, this is IT help desk, we’re calling to help you deal with the email flood.” They walk you through steps that quietly install remote access, like Xray-core. Here’s the scary part: once Aurora had access, researchers saw them using an AI coding assistant called Cursor to script VPNs, scan internal systems, and hunt for domain privileges. The hard work is automated. If your inbox gets bombed and “IT help desk” calls out of the blue, hang up and call IT back using our official number or ticketing system before you do anything.

Similar attacks

Hackers Talked Cursor AI Into “Legal” Test Mode

Hackers Talked Cursor AI Into “Legal” Test Mode

Investigators found chat logs showing Russian-speaking criminals repeatedly claiming they were running “legitimate security tests” to get Cursor’s AI agent to help during real intrusions. The logs indicate the AI assisted with tasks like network scanning, privilege enumeration, VPN setup, and…

August 28, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
Levi’s Breach Tied to Phone-to-Phish Workflow

Levi’s Breach Tied to Phone-to-Phish Workflow

Levi Strauss disclosed a breach after attackers used social engineering to access three employees’ work computers and steal some corporate data. Separately, reporting and Google’s tracking describe a broader campaign where criminals call employees while posing as coworkers or IT, then send them to…

August 10, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
AI-Aided Crypto Scam Used Phishing + Vishing Combo

AI-Aided Crypto Scam Used Phishing + Vishing Combo

Researchers found a crypto fraud operation that used AI-assisted tooling to sift and verify over 100,000 phone numbers, then target confirmed crypto users. The campaign used a one-two approach: phishing messages that included a case/verification code, followed by phone calls that referenced those…

August 19, 2026
“Ransom Busters” Emails Victims for $60K “Help”

“Ransom Busters” Emails Victims for $60K “Help”

A criminal actor calling itself “Ransom Busters” is emailing organizations that recently suffered ransomware incidents, claiming it hacked ransomware groups’ servers and can delete the victim’s stolen data for a $20,000–$60,000 fee. The messages ask to speak with the CEO or IT leadership and…

August 18, 2026