VAPT is the name given to an automated, multi-stage offensive security framework observed abusing an exposed, unauthenticated Ollama server as its reasoning backend. The framework appears designed to integrate large language model inference directly into the attack pipeline, using the model to perform service fingerprinting, vulnerability matching, web reconnaissance, proof-of-concept exploit generation, blind SQL injection payload creation, credential extraction, arbitrary file-read planning, privilege-escalation decision support, and orchestration of exploitation steps through to command execution. The tool identifies itself with distinctive internal markers and includes an orchestration component intended to autonomously pursue compromise objectives. Observed functionality indicates a backend-agnostic design capable of working with both commercial and self-hosted models, suggesting it can be repointed between paid AI services and exposed local inference infrastructure. The framework exposed helper capabilities to the model including request handling, JWT forgery support, PHP object injection gadget generation, SSRF scanning, and object injection scanning. A second orchestrator variant labeled PROPOSE-ONLY referenced a deterministic verifier and a stated zero-false-positive design goal, indicating an effort to constrain autonomous actions with validation logic. The most heavily used stage during the observed activity was credential and secret extraction, and the overall workflow supported compromise confirmation and post-compromise decision-making. During the observation window, activity was associated with residential-origin infrastructure in India. However, the observed targets were limited to private lab-style address space and fictitious applications, indicating tool development, testing, or tuning rather than confirmed attacks against public victims during that period. VAPT represents an evolution of LLM-enabled offensive tooling in which exposed self-hosted model capacity is used as an unattributed execution and reasoning engine for autonomous intrusion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.