HexStrike AI is an open-source AI-based attack and penetration-testing framework, also referred to as HexStrike-AI, that uses generative AI and model context protocols (MCPs) to orchestrate traditional red-team tooling. The provided content places it at AIM3 Level 3 (Optimizing), describing it as an AI-enabled red teaming framework that augments attacker workflows through tool orchestration rather than fully autonomous malware behavior. It is associated with automated reconnaissance and credential-attack use cases, and reporting from September 2025 lists it alongside BruteForce AI as an open-source AI-based attack tool. Additional reporting states that criminals have turned HexStrike AI into a weapon for discovering or exploiting fresh vulnerabilities. More broadly, the surrounding reporting situates HexStrike AI within the expanding ecosystem of offensive AI tooling distributed through open-source channels such as GitHub and similar platforms, alongside tools such as WormGPT, FraudGPT, EvilGPT, KawaiiGPT, Xanthorox, and BruteForce AI. No specific indicators of compromise, infection vector, or victim industry targeting are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The approach needs no software exploit. The attacker simply configures an agent or client ... to use the exposed endpoint as its model backend.
Find an unauthenticated AI backend Repurpose it as free, anonymous compute for an offensive AI workload.
The approach needs no software exploit. The attacker simply configures an agent or client ... to use the exposed endpoint as its model backend.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source AI-based attack framework.
AI-based hacking tool referenced as part of the ecosystem of offensive AI tools distributed on dark web and other platforms.
Open-source AI-powered penetration testing framework that uses multiple AI agents to drive traditional red team tools such as nmap.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.