HexStrike AI is an open-source offensive security orchestration framework implemented as an MCP server and packaged for Kali Linux. It is designed to let an AI agent autonomously invoke and coordinate more than 150 offensive security tools, enabling AI-assisted penetration-testing and post-compromise workflows. Observed activity associated with HexStrike AI involved directing a desktop LLM client at exposed self-hosted AI inference infrastructure and supplying the full offensive toolset to the backend, indicating use of third-party model servers as anonymous compute for offensive operations rather than reliance on a software exploit. The framework’s exposed capabilities, as observed in operational use, support reconnaissance, scanning, brute-force activity, exploitation support, cloud and container assessment, payload generation, file manipulation, and arbitrary code execution through integrated offensive tooling. In the observed case, the operator first enumerated available models on the exposed backend and then staged the HexStrike AI tool definitions, consistent with preparation for autonomous offensive use. No specific victim was identified in that incident, and the activity appeared to be staging or capability testing rather than a confirmed live intrusion. HexStrike AI should be understood primarily as an offensive AI-enabled framework rather than a well-established named intrusion set. Available reporting supports its use in unauthorized offensive experimentation against exposed Ollama infrastructure, but does not provide high-confidence attribution to a nation-state, a stable threat cluster, or a defined long-term campaign history.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Autonomous penetration testing framework observed being staged through an exposed Ollama instance, with its offensive toolset sent to the hijacked backend for potential future attack operations.
An offensive AI framework used via a hijacked exposed Ollama backend to stage autonomous use of a large arsenal of security tools. In this case the operator appeared to be setting up and testing the backend rather than assigning a live target.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.