Threat Advisory

Aurora Ransomware Exfiltrates Content to S3 Buckets Utilizing Advanced Techniques

Threat: Ransomware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Aurora is a ransomware operation targeting organizations across multiple countries, with activity involving both data theft and encryption of virtualized infrastructure. The operation has been observed deploying a Linux-based ransomware variant designed specifically to compromise VMware ESXi environments, while also leveraging an AI-powered coding assistant to support hands-on intrusion and exploitation activities within victim networks.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Aurora is a ransomware operation targeting organizations across multiple countries, with activity involving both data theft and encryption of virtualized infrastructure. The operation has been observed deploying a Linux-based ransomware variant designed specifically to compromise VMware ESXi environments, while also leveraging an AI-powered coding assistant to support hands-on intrusion and exploitation activities within victim networks.[emaillocker id="1283"]

The Aurora Linux ransomware encrypts files using ChaCha20 and protects the associated session keys with an embedded RSA-4096 public key. In ESXi mode, the malware identifies running virtual machines, forcibly terminates them to release locks on virtual disks, and encrypts VMware-related files including VMDK, VMX, VMSD, VMSN, NVRAM, VMEM, VSWP, and LOG files while avoiding critical hypervisor system volumes. The operators also used a custom ESXi discovery tool to identify ESXi hosts and vCenter servers by enumerating internal networks and scanning relevant ports. In compromised environments, Cursor Agent running Claude Sonnet was used to assist with reconnaissance, network scanning, privilege enumeration, VPN or proxy configuration, NTLM relay attempts, and certificate-based attacks. A separate activity cluster involved SQL Server command execution, privilege escalation, domain replication attacks, and data exfiltration to self-hosted S3-compatible infrastructure.

The Aurora operation demonstrates an increasingly integrated ransomware approach that combines virtualization-focused encryption, network reconnaissance, credential and privilege abuse, data exfiltration, and AI-assisted exploitation. The ability to target ESXi infrastructure can significantly disrupt multiple virtual machines simultaneously, while the use of AI agents can accelerate reconnaissance and attack execution. Organizations should strengthen ESXi and vCenter security, restrict administrative access, monitor unusual network and authentication activity, protect domain credentials, and detect unauthorized use of AI-assisted tooling within enterprise environments.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Lateral Movement T1021.001 Remote Services Remote Desktop Protocol
Exfiltration T1567.002 Exfiltration Over Web Service Exfiltration to Cloud Storage
Impact T1486 Data Encrypted for Impact -

 

REFERENCES:

The following reports contain further technical details:

https://securityonline.info/aurora-ransomware-esxi/

https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation

[/emaillocker]
crossmenu