CyberStrikeAI is an open-source, AI-native offensive security tool written in Go that has been actively leveraged by threat actors in campaigns targeting edge devices, particularly Fortinet FortiGate appliances. Public reporting describes it as integrating more than 100 security tools and providing capabilities for vulnerability discovery, attack-chain analysis, knowledge retrieval, intelligent orchestration, result visualization, role-based testing, specialized skills, lifecycle management, and a web dashboard for managing active operations. Researchers assessed that these features lower the technical barrier for large-scale automated exploitation.
Team Cymru reported CyberStrikeAI was used in an AI-assisted campaign targeting FortiGate devices and analyzed activity associated with IP address 212.11.64.250, where a CyberStrikeAI banner was observed on an exposed service. Team Cymru also observed NetFlow communications between that infrastructure and FortiGate targets. Separate reporting cited another automated mass-scanning campaign targeting FortiGate devices in which CyberStrikeAI was also used. Amazon Threat Intelligence previously reported AI-augmented infrastructure targeting FortiGate appliances at scale, including compromise of more than 600 devices across 55 countries.
The tool is publicly hosted on GitHub and maintained under the alias Ed1s0nZ, described in the reporting as a China-based developer. Team Cymru observed 21 unique IP addresses running CyberStrikeAI between January 20 and February 26, 2026, with infrastructure primarily hosted in China, Singapore, and Hong Kong, and additional servers in the United States, Japan, and Switzerland. Reporting further states that the developer has published other offensive or dual-use projects, including PrivHunterAI, InfiltrateX, VigilantEye, banana_blackmail, and ChatGPTJailbreak.
Multiple reports cited in the content assess that the developer may have ties to Chinese government-linked or state-aligned entities, including interactions with Knownsec 404 and references to CNNVD recognition later removed from public materials. One report assesses a high probability that CyberStrikeAI could be adopted by Chinese state-sponsored APT groups, although the observed FortiGate scanning activity discussed in the reporting was attributed to a suspected Russian-speaking threat actor. High-confidence observable information directly mentioned in the content includes the IP address 212.11.64.250 associated with CyberStrikeAI-linked FortiGate scanning activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source framework reportedly used in a separate automated mass scanning campaign targeting FortiGate devices.
An open-source AI-enabled offensive security tool discussed as potentially having China-linked developer ties (per the source).
An open-source, Go-based AI-augmented offensive security/testing platform that integrates 100+ security tools to support vulnerability discovery, attack-chain analysis, knowledge retrieval, and visualization; observed being used for automated mass scanning of vulnerable Fortinet FortiGate appliances.
An open-source, Go-based AI-orchestrated offensive security platform that integrates 100+ security tools and provides a web dashboard to automate and scale reconnaissance and exploitation against targets (notably Fortinet FortiGate edge devices), lowering the barrier for large-scale automated network exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.