“Vibe Hacking”: How Aurora Ransomware Used an AI Agent to Reach ESXi
About Event
Recently published threat intelligence documents the Aurora ransomware group using Cursor Agent, running Claude Sonnet, for hands-on exploitation across ten target organizations between April and May 2026: scanning internal subnets, mapping domain privileges, and attempting relay and certificate attacks. A human operator supervised it in Russian, with standing rules meant to avoid tripping alerts.
The intrusions ended at the hypervisor. Aurora's Linux encryptor force-kills every running VM by World ID to release disk locks, encrypts VM files, and spares the boot volumes so ESX stays up to display the ransom demand.
Join Vali Cyber’s Nathan Montierth for a walkthrough of the chain and how ZeroLock detects the behavior that precedes encryption on ESX.
Speaker
Nathan Montierth
Event Partners
Vali Cyber® secures where attacks have the most impact: mission critical systems. While most defenses focus on endpoints, Vali Cyber identified Linux and hypervisors as critical yet under protected. Built for this reality, ZeroLock®delivers preemptive security with CLI-MFA, exploit prevention, deep hypervisor visibility, and AI-driven behavioral detection. By operating at the hypervisor layer, ZeroLock stops threats in real time without performance impact or added overhead. If incidents occur, automated rollback restores workloads in seconds, ensuring uptime. Recognized by Gartner as a Key Startup in Security Software, Vali Cyber leads by protecting the foundation of modern infrastructure others overlook.