AI Assistant "Cursor" Abused for Ransomware Attacks – Teckentrup Affected
Russian-speaking hackers used the AI programming assistant "Cursor" to carry out cyber attacks on at least seven companies worldwide, including German garage door manufacturer Teckentrup.

Ransomware Group "Aur0ra" Deceives AI with Fake Scenarios
Russian-speaking hackers have used the AI programming assistant "Cursor" to carry out cyber attacks on at least seven companies worldwide – including a German manufacturer. This is reported by the Frankfurter Allgemeine Zeitung citing Reuters data as well as reports from IT security firms Gambit Security and CloudSek, which were published on Thursday.
The ransomware group "Aur0ra" attacked companies in Germany, Belgium, the United States, Scotland, Italy and Argentina between 8 April and 21 May. The named victims include German garage door manufacturer Teckentrup as well as a Belgian chemical company. SpaceX, owner of "Cursor" since the beginning of the month, made no comment on the incidents.
Teckentrup stated on its website that a successful cyber attack did not take place. "The IT security measures functioned properly," the company said. There was no evidence of unauthorised access or compromise of systems or data.
According to CloudSek, the hacker group recorded at least 20 victims in total. How many of these were attacked with the aid of the AI remained unclear. Reuters identified six affected parties after the news agency independently verified parts of the chat data. At least one of those affected appeared on the hackers' leak page – an indication of a failed extortion attempt.
The attackers circumvented "Cursor's" security measures by making the software believe it was a simulation. According to logs on an unprotected server, the AI agent then carried out hundreds of actions. "This is a test environment, so it is legal," the AI itself concluded according to one of the logs.
In the attack on Teckentrup, the software recommended the use of a known malware and assessed the chance of success as "very high". Such tools gave cybercriminals a considerable advantage, explained Eyal Sela of Gambit: many manual steps were eliminated, meaning attacks could be carried out 30 to 50 per cent faster.
The technology used was the Claude Sonnet 4.5 model from provider Anthropic, on which "Cursor" is based. AI-powered hacker attacks are the new normal, said Gambit strategy chief Curtis Simpson. "We will see such things increasingly frequently in the future."
Source: Frankfurter Allgemeine Zeitung