Hacking ESX is as easy as 1, 2, 3. Literally.

Between April 8 and May 21, 2026, an operator from the Aurora ransomware group worked through ten victim networks with help from an AI coding assistant. He typed instructions, and the AI worked out the commands, ran them, and reported back.  

Researchers recovered those session logs from exposed attacker infrastructure and published them in August. It is one of the first documented AI-assisted ransomware attacks on ESX, and a clear look at a technique some have called “vibe hacking”. 

 

What is Vibe Hacking? 

Vibe hacking refers to describing what you want a cyber attack to accomplish and letting an AI agent work out the technical steps. The name borrows from vibe coding, where a developer describes a feature, and the AI writes the code. 

The operator supplies the goal and ground rules; the agent writes the commands, fixes its own mistakes, and reports back. Expertise that once took years to build becomes something an attacker can rent by the month. 

Most coverage has focused on AI social engineering: phishing at scale, cloned voices, ransom notes tailored to each victim. But Aurora is the harder version — an AI working hands-on inside a live corporate network. 

 

What Happened in the Aurora Campaign 

Aurora’s operator used Cursor Agent, a coding assistant running Claude Sonnet. He gave it a way into each target, usually stolen credentials, and set it loose. The instructions were casual. Sometimes a goal: “tell me what rights the user has,” and occasionally a specific tool. In several sessions, the agent offered a numbered list of next steps and the operator simply replied with a number. 

From there, it did what an experienced intruder does: mapped the internal network, worked out who held administrator rights, tricked servers into handing over credentials, and abused the company’s certificate system to issue itself new identities.  

The agent also ran a custom script built to hunt for hypervisors, the servers that host every virtual machine in a data center. It learns the internal address ranges, probes for systems that answer like ESX, and records the version running. Aurora went looking for the hypervisor from the start for a simple reason: encrypt one host and every virtual machine on it goes down together. 

The ransomware has a dedicated ESX mode to finish the job. It lists the running virtual machines and force-shuts them down, because a running VM keeps its disk file locked, and that file must be free before it can be encrypted. It then scrambles the virtual disks with a key only Aurora holds. It leaves the host’s boot files untouched, so the server still starts and plants the ransom demand in the SSH login banner, where the first administrator who logs in to investigate reads it before anything else. 

 

The Three Major Takeaways from Aurora’s Attack 

Three details stand out. 

The agent failed constantly. Most of its commands missed on the first attempt and needed several rounds of correction. Retries that would have cost a human operator hours, only cost this one a follow-up sentence. 

Meanwhile, the operator stayed disciplined. He repeated the same restrictions at every victim and held the agent to them: avoid the techniques that trip standard alarms, don’t lock anyone out of their account, don’t add anything new to the domain. Experienced judgment plus a tireless assistant is a combination built for speed and scale. 

Aurora’s path to ransomware did not look like malware. Before encryption began, Aurora relied on legitimate tools and commands rather than obvious malicious files. Detection that waits to recognize a known-bad file or a repeat server has little to work with when the intrusion is assembled fresh at each victim. 

 

How ZeroLock Stops an AI-Assisted ESX Ransomware Attack 

ZeroLock® sits on the hypervisor and judges behavior as it happens, so it does not depend on recognizing something it has seen before. 

  • Stolen credentials stop being enough. Aurora’s agent worked with credentials the operator handed it. ZeroLock brings multi-factor authentication to the hypervisor command line, so a password alone no longer opens a session, and every failed attempt raises an alert instead of passing silently. 
  • The shutdown step gets blocked. Ransomware has to stop the virtual machines before it can encrypt their disks. ZeroLock’s rules govern which programs may run and which files they may touch, breaking the sequence before a single virtual disk is scrambled. 
  • Behavior gives the payload away. ZeroLock identifies ransomware by what it does rather than what it matches, stopping traditional and fileless attacks with greater than 98% efficacy.  
  • Damage gets undone. If encryption begins, ZeroLock kills the process, removes the attacker, and restores affected files to their pre-attack state in seconds, with full forensic detail for the investigation. 

 

Next Steps 

An AI agent let Aurora’s operator move faster. Preemptive controls that verify identity at the command line, watch behavior on the hypervisor, and repair damage on their own hold up no matter how fast the other side moves. 

Join us on September 24 at 11:00 AM CST for “Vibe Hacking”: How Aurora Ransomware Used an AI Agent to Reach ESXi, a full walkthrough with the Vali Cyber threat intelligence team. 

Register Now