Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

CyberStrikeAI

CyberStrikeAI is an open-source, AI-native offensive security/testing platform (OST) written in Go and hosted on GitHub (maintained by a China-based developer using the alias “Ed1s0nZ”). It integrates 100+ security tools and provides AI-driven orchestration for vulnerability discovery, attack-chain analysis, knowledge retrieval, result visualization, and a web dashboard for monitoring operations; reporting states it lowers the barrier to large-scale automated exploitation.

Threat activity: Team Cymru reported CyberStrikeAI being leveraged in an AI-assisted campaign targeting edge devices, particularly Fortinet FortiGate appliances. In that reporting, automated mass scanning for vulnerable FortiGate devices was associated with IP 212.11.64[.]250 (attributed in the report to a suspected Russian-speaking threat actor). Team Cymru identified a “CyberStrikeAI” banner on an exposed host and, via global NetFlow monitoring, observed communications between 212.11.64.250 and FortiGate targets. Amazon Threat Intelligence previously reported an unknown attacker using generative AI services (including Anthropic Claude and DeepSeek) to compromise more than 600 FortiGate appliances across 55 countries.

Infrastructure observations: Between January 20 and February 26, 2026, Team Cymru observed 21 unique IPs running CyberStrikeAI, primarily hosted in China, Singapore, and Hong Kong, with additional servers in the United States, Japan, and Switzerland.

Attribution/associations (as reported): Team Cymru assessed CyberStrikeAI had ties to a China-based developer with possible links to Chinese government–aligned organizations, including entities tied to China’s Ministry of State Security (MSS). Reporting noted interactions with Knownsec 404 (described by DomainTools as a state-aligned cyber contractor) and that the developer removed references to CNNVD recognition (CNNVD described as overseen by the MSS), suggesting an effort to obscure potential state associations.

Indicators explicitly mentioned in the content: IP address 212.11.64[.]250 (CyberStrikeAI banner; FortiGate-targeting scanning/communications).

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Reconnaissance

2 techniques
T1595Active ScanningEvidence3

Reconnaissance, vulnerability discovery, exploitation -- these now run as structured, repeatable sequences rather than commands that require real technical knowledge to chain correctly.

T1595.002Vulnerability ScanningEvidence1

“PrivHunterAI and InfiltrateX, which utilize AI engines to automate vulnerability detection… Automated privilege escalation vulnerability scanning tool.”

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence3

last week, security researchers detected its use in a successful attack against Fortinet’s Fortigate appliances.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.