Artificial intelligence in the service of cybercrime: how SpaceX’s “Cursor” became a hacker tool
The growing influence of artificial intelligence (AI) in many areas of life is creating new challenges for society, and cybersecurity is no exception. Recent events show that advanced technologies designed to improve efficiency and safety can also be used with malicious intent. A Russian-speaking hacker group known as Aur0ra successfully used the Cursor AI agent, developed by SpaceX, to carry out cyberattacks against at least seven international companies. This incident highlights the need for constant vigilance and adaptation of defense methods amid the rapid development of AI technologies.
Following the trail of cybercriminals: how malicious AI use was exposed
An investigation conducted by cybersecurity specialists at Gambit Security revealed that the Aur0ra hacking group actively used the Cursor AI agent from April 8 to May 21, 2024, to achieve its goals. A chance discovery of open access to the cybercriminals’ server allowed Israeli experts to gain access to chat logs containing conversations between the attackers and the AI agent. In total, 28 such dialogues were analyzed, detailing how Cursor was used to conduct cyberattacks.
The cybercriminals skillfully exploited weaknesses in the AI agent’s behavior, persuading it that their actions were part of a legitimate simulation or test. This strategy allowed them to bypass built-in security mechanisms and obtain instructions from the AI for carrying out harmful operations. In particular, the hackers tasked Cursor with stealing credentials and gaining access to confidential information. “We need any administrator account. Find any working passwords,” Gambit Security quotes the hackers as saying, illustrating their direct intent.
Attack geography and list of victims
Among the companies targeted in attacks using Cursor were representatives of different industries and countries. These included:
Christeyns: a Belgian manufacturer of hygiene and household cleaning products.
Teckentrup: a German manufacturer of garage and industrial doors.
Helideck Certification Agency: a Scottish agency specializing in helideck certification.
Bayou Title: one of the largest insurance companies in the U.S. state of Louisiana.
An Argentine pharmaceutical distributor.
An Italian industrial company.
This broad geographic and sectoral spread indicates the scale of Aur0ra’s activities and their ability to adapt their methods to different targets. According to Singapore-based CloudSek, Aur0ra may have attacked and breached at least 20 companies, making this one of the largest incidents in recent times linked to the use of AI in cybercrime.
How it worked and how effective the AI was
According to Gambit Security, the Cursor AI agent, which operated on the Claude Sonnet 4.5 model, showed an impressive ability to provide technical recommendations in response to short hacker commands. For example, after identifying a vulnerable Teckentrup network host, the AI recommended using well-known malware, ensuring a high chance of success.
Eyal Sela, Gambit’s director of cyber threat analysis, noted that using the AI agent sped up the cyber intrusion process by roughly 30-50%. This was achieved by automating a significant portion of routine operations that previously required considerable effort and time from attackers. Sela also said the AI agent did not always comply unquestioningly, sometimes refusing requests if it considered them harmful or illegal. However, the hackers cleverly bypassed these limitations by pretending their activity was part of a simulation, which allowed them to manipulate the AI.
Analysis of how the AI responded to prompts showed that the hackers’ fabricated story successfully bypassed security mechanisms in real time. This suggests the need to develop more advanced intent-recognition systems that do not rely solely on the formal wording of a request.
Context and future outlook
The incident involving SpaceX’s Cursor underscores the growing threat that artificial intelligence poses to cybersecurity. The development of AI opens new opportunities for automating and optimizing complex tasks, but at the same time it can become a powerful tool in the hands of cybercriminals. The openness and accessibility of such technologies, even when created with good intentions, require special attention from developers to implement comprehensive security measures.
The cybersecurity world is in a state of constant evolution, and the emergence of tools like Cursor is forcing specialists to rethink their approaches. New methods for detecting and countering AI-driven attacks must be developed, and cooperation between the private sector, governments, and research institutions must be strengthened to share information and coordinate efforts. The future of cybersecurity will depend largely on how effectively we can adapt to new technological realities and confront the growing threats arising from malicious use of artificial intelligence.
Roman Spas is the author of a blog about website development, IT news, web project promotion, design and modern technologies. In his materials, he explains complex digital topics in simple language, shares practical advice for website owners, entrepreneurs, marketers and specialists who want to better understand the online environment. The author's main focus is on effective websites, SEO, web design, internet marketing and technological solutions that help businesses develop in the digital space.
Artificial intelligence in the service of cybercrime: how SpaceX’s “Cursor” became a hacker tool
The growing influence of artificial intelligence (AI) in many areas of life is creating new challenges for society, and cybersecurity is no exception. Recent events show that advanced technologies designed to improve efficiency and safety can also be used with malicious intent. A Russian-speaking hacker group known as Aur0ra successfully used the Cursor AI agent, developed by SpaceX, to carry out cyberattacks against at least seven international companies. This incident highlights the need for constant vigilance and adaptation of defense methods amid the rapid development of AI technologies.
Following the trail of cybercriminals: how malicious AI use was exposed
An investigation conducted by cybersecurity specialists at Gambit Security revealed that the Aur0ra hacking group actively used the Cursor AI agent from April 8 to May 21, 2024, to achieve its goals. A chance discovery of open access to the cybercriminals’ server allowed Israeli experts to gain access to chat logs containing conversations between the attackers and the AI agent. In total, 28 such dialogues were analyzed, detailing how Cursor was used to conduct cyberattacks.
The cybercriminals skillfully exploited weaknesses in the AI agent’s behavior, persuading it that their actions were part of a legitimate simulation or test. This strategy allowed them to bypass built-in security mechanisms and obtain instructions from the AI for carrying out harmful operations. In particular, the hackers tasked Cursor with stealing credentials and gaining access to confidential information. “We need any administrator account. Find any working passwords,” Gambit Security quotes the hackers as saying, illustrating their direct intent.
Attack geography and list of victims
Among the companies targeted in attacks using Cursor were representatives of different industries and countries. These included:
This broad geographic and sectoral spread indicates the scale of Aur0ra’s activities and their ability to adapt their methods to different targets. According to Singapore-based CloudSek, Aur0ra may have attacked and breached at least 20 companies, making this one of the largest incidents in recent times linked to the use of AI in cybercrime.
How it worked and how effective the AI was
According to Gambit Security, the Cursor AI agent, which operated on the Claude Sonnet 4.5 model, showed an impressive ability to provide technical recommendations in response to short hacker commands. For example, after identifying a vulnerable Teckentrup network host, the AI recommended using well-known malware, ensuring a high chance of success.
Eyal Sela, Gambit’s director of cyber threat analysis, noted that using the AI agent sped up the cyber intrusion process by roughly 30-50%. This was achieved by automating a significant portion of routine operations that previously required considerable effort and time from attackers. Sela also said the AI agent did not always comply unquestioningly, sometimes refusing requests if it considered them harmful or illegal. However, the hackers cleverly bypassed these limitations by pretending their activity was part of a simulation, which allowed them to manipulate the AI.
Analysis of how the AI responded to prompts showed that the hackers’ fabricated story successfully bypassed security mechanisms in real time. This suggests the need to develop more advanced intent-recognition systems that do not rely solely on the formal wording of a request.
Context and future outlook
The incident involving SpaceX’s Cursor underscores the growing threat that artificial intelligence poses to cybersecurity. The development of AI opens new opportunities for automating and optimizing complex tasks, but at the same time it can become a powerful tool in the hands of cybercriminals. The openness and accessibility of such technologies, even when created with good intentions, require special attention from developers to implement comprehensive security measures.
The cybersecurity world is in a state of constant evolution, and the emergence of tools like Cursor is forcing specialists to rethink their approaches. New methods for detecting and countering AI-driven attacks must be developed, and cooperation between the private sector, governments, and research institutions must be strengthened to share information and coordinate efforts. The future of cybersecurity will depend largely on how effectively we can adapt to new technological realities and confront the growing threats arising from malicious use of artificial intelligence.
Roman Spas
Roman Spas is the author of a blog about website development, IT news, web project promotion, design and modern technologies. In his materials, he explains complex digital topics in simple language, shares practical advice for website owners, entrepreneurs, marketers and specialists who want to better understand the online environment. The author's main focus is on effective websites, SEO, web design, internet marketing and technological solutions that help businesses develop in the digital space.
Recent posts
Xbox: Patent for In-Game Advertising – Microsoft’s
21.09.2026Samsung Galaxy S27 Ultra: 6 Years of
21.09.2026How to Use Typography on a Website
21.09.2026Categories