# Hacktron AI

> As of 2026-09-27, Hacktron AI is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability. ATT&CK coverage spans 25 techniques across 11 tactics in 2 of 2 tracked threats. Most-observed techniques: AML.T0054 (LLM Jailbreak), T1059.004 (Unix Shell), T1082 (System Information Discovery).

- **Tracked threats:** 2
- **Categories:** VULNERABILITY
- **As of:** 2026-09-27

## ATT&CK techniques observed

25 techniques observed across 2 of 2 tracked threats. Tactics: Resource Development (4), Credential Access (3), Discovery (3), Initial Access (3), Collection (2), Execution (2).

- [AML.T0054](https://intel.threadlinqs.com/technique/AML.T0054) LLM Jailbreak — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1059.004](https://intel.threadlinqs.com/technique/T1059.004) Unix Shell — Execution — observed in 2 of 2 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 2 of 2 tracked threats
- [T1213.003](https://intel.threadlinqs.com/technique/T1213.003) Data from Information Repositories — Collection — observed in 2 of 2 tracked threats
- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 2 of 2 tracked threats
- [T1550.001](https://intel.threadlinqs.com/technique/T1550.001) Application Access Token — Lateral Movement — observed in 2 of 2 tracked threats
- [T1583.006](https://intel.threadlinqs.com/technique/T1583.006) Acquire Infrastructure: Web Services — Resource Development — observed in 2 of 2 tracked threats
- [T1587.004](https://intel.threadlinqs.com/technique/T1587.004) Exploits — Resource Development — observed in 2 of 2 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 1 of 2 tracked threats
- [T1068](https://intel.threadlinqs.com/technique/T1068) Exploitation for Privilege Escalation — Privilege Escalation — observed in 1 of 2 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 1 of 2 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 1 of 2 tracked threats
- [T1199](https://intel.threadlinqs.com/technique/T1199) Trusted Relationship — Initial Access — observed in 1 of 2 tracked threats

## Tracked threats

- [AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access](https://intel.threadlinqs.com/threat/TL-2026-2568) — HIGH
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — HIGH

## Related CVEs

1 CVE referenced by tracked Hacktron AI activity.

- [CVE-2026-32882](https://intel.threadlinqs.com/cve/CVE-2026-32882)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Hacktron%20AI
