Threat reportThreat IntelligenceTL-2026-2881
Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated Large-Scale Attacks, incl. CVE-2025-7775 Citrix NetScaler
Desktop AI Supercomputers, Uncensored Models and Agentic (TL-2026-2881), also tracked as HexStrike-AI abuse, is a high-severity tracked intrusion set scored CVSS 9.8, first published 2026-10-03. It has no confirmed attribution, affects Citrix / Cloud Software Group NetScaler ADC and NetScaler Gateway, references 3 CVEs (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424), maps to 13 MITRE ATT&CK / ATLAS techniques (AML.T0018, AML.T0053, AML.T0054), and is covered by 9 detection rules and 10 indicators of compromise.
- CVSS
- 9.8/10High
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 13MITRE ATT&CK / ATLAS
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 10Indicators of compromise
Key facts for TL-2026-2881
- Threat ID
- TL-2026-2881
- Also known as
- HexStrike-AI abuse, AI-orchestrated automated exploitation, GTG-1002 (referenced context)
- Severity
- HIGH
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, finance, chemical, government administration, telecoms
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 10
Malware and tooling in Desktop AI Supercomputers, Uncensored Models and Agentic
Malware and tooling: Abliterated open-weight LLMs (Hugging Face), Claude Code, FastMCP, Heretic, HexStrike-AI, Nmap, Nuclei
How Desktop AI Supercomputers, Uncensored Models and Agentic works
Netlas reports that affordable local AI hardware (NVIDIA DGX Spark), abliterated open-weight models and MCP-based agentic orchestration are converging to make autonomous, large-scale attacks cheap. Check Point documented threat actors pointing the open-source HexStrike-AI MCP framework at Citrix NetScaler CVE-2025-7775 within 12 hours of disclosure, with claims of exploitation compressed from days to under ten minutes.
Netlas (Bedrettin Ortak, 2026-08-05) argues that three trends now combine: (1) desktop AI hardware such as the NVIDIA DGX Spark (1 petaFLOP FP4, 128 GB unified memory, 4 TB SSD, $4,699 as of August 2026; fine-tuning of models up to ~70B parameters and inference up to ~200B), (2) abliterated open-weight models, where refusal behaviour is removed by editing weights (technique popularised by FailSpy building on Arditi et al. 2024; automated by the Heretic tool; an Alice research study of April 2026 reported harmful-prompt compliance rising from 5.8% to 98% across 5 models after abliteration), and (3) agentic orchestration over the Model Context Protocol (MCP), which lets a language model drive many offensive tools autonomously.
The concrete incident cited is HexStrike-AI, an MIT-licensed open-source MCP server (GitHub 0x4m4/hexstrike-ai, published by Muhammad Osama / OTT Cybersecurity LLC) that exposes 150+ security tools (Nmap, Nuclei with 4,000+ templates, browser automation, cloud assessment, 12+ specialised agents) to MCP-capable clients such as Claude Desktop, VS Code Copilot, Cursor and Roo Code. Check Point Research (2025-09-02) reported that within about 12 hours of Citrix's 2025-08-26 advisory for three NetScaler zero-days (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424), underground-forum actors were discussing using HexStrike-AI against them. Claims included unauthenticated RCE on CVE-2025-7775, webshell deployment for persistence, parallel scanning of thousands of IPs, and sale of compromised/vulnerable instances. The 'under 10 minutes' timing is an actor claim relayed by Check Point, not independently measured.
CVE-2025-7775 is a memory overflow (CWE-119) in NetScaler ADC/Gateway leading to RCE and/or DoS, CVSS v3.1 9.8 / v4.0 9.2, exploitable without authentication on appliances configured as Gateway (VPN vserver, ICA Proxy, CVPN, RDP Proxy), AAA vservers, LB vservers bound to IPv6 services, or CR vservers of type HDX. It was added to CISA KEV on 2025-08-26 (federal due date 2025-08-28). Shadowserver counted ~28,000 exposed endpoints initially and ~8,000 by 2025-09-02.
For context the article also cites GTG-1002, assessed by Anthropic with high confidence as a Chinese state-sponsored group that in mid-September 2025 used Claude Code with MCP-connected scanners and password crackers to run an espionage campaign against ~30 targets (technology, finance, chemical manufacturing, government), with the AI performing an estimated 80-90% of tactical work and humans making 4-6 decision points per campaign. GTG-1002 bypassed safeguards through role-play (posing as defensive testers) and task decomposition, not abliteration; Claude's hallucinated credentials were a limiting factor. XBOW, a legitimate autonomous pentester that topped the HackerOne US leaderboard in June 2025, is cited as evidence of the speed of autonomous offense. There is no single named adversary or new malware in the Netlas article; this record tracks the capability trend and the HexStrike-AI/NetScaler abuse.
MITRE ATT&CK / ATLAS techniques used in TL-2026-2881
Persistence
AML.T0018 Manipulate AI Model; T1505.003 Web Shell
Execution
AML.T0053 AI Agent Tool Invocation; T1059 Command and Scripting Interpreter
Defense Evasion
Discovery
T1046 Network Service Discovery
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Credential Access
Resource Development
T1588.002 Tool; T1588.006 Vulnerabilities; T1588.007 Artificial Intelligence
Reconnaissance
Affected products and versions in Desktop AI Supercomputers, Uncensored Models and Agentic
- Citrix / Cloud Software Group — NetScaler ADC and NetScaler Gateway (CVE-2025-7775)
Vulnerable versions: 13.1 before 13.1-59.22; 14.1 before 14.1-47.48; 12.1-FIPS/NDcPP before 12.1-55.330; 13.1-FIPS/NDcPP before 13.1-37.241
Fixed in: 13.1-59.22; 14.1-47.48; 12.1-FIPS/NDcPP 12.1-55.330; 13.1-FIPS/NDcPP 13.1-37.241
Remediation for Desktop AI Supercomputers, Uncensored Models and Agentic
Patches
- NetScaler ADC/Gateway 14.1-47.48 or later
- NetScaler ADC/Gateway 13.1-59.22 or later
- NetScaler ADC 13.1-FIPS/NDcPP 13.1-37.241 or later
- NetScaler ADC 12.1-FIPS/NDcPP 12.1-55.330 or later
Immediate actions
- Upgrade NetScaler ADC/Gateway to 14.1-47.48+, 13.1-59.22+, 13.1-FIPS/NDcPP 13.1-37.241+ or 12.1-FIPS/NDcPP 12.1-55.330+ and hunt for webshells on appliances that were exposed before patching
- Inventory NetScaler appliances configured as Gateway, AAA, IPv6 LB or CR/HDX vservers and prioritise them
- Check CISA KEV for CVE-2025-7775 and meet the same-day patch expectation
Workarounds
- Reduce exposure of Gateway/AAA virtual servers to the internet until patched
- Follow vendor mitigations per CISA KEV guidance or discontinue use if mitigations are unavailable
Longer-term hardening
- Build automated same-day patching and validation pipelines for internet-facing edge devices
- Continuous external attack-surface discovery
- Automated detection and response operating at machine speed; behavioural monitoring rather than payload signatures
- Least-privilege scoping and action logging for internal agent/MCP tools
- Threat-intelligence monitoring of underground forums for rapid tooling changes
CVEs associated with Desktop AI Supercomputers, Uncensored Models and Agentic
CVE-2025-7775, CVE-2025-7776, CVE-2025-8424
Weaknesses (CWE) in Desktop AI Supercomputers, Uncensored Models and Agentic
Timeline of Desktop AI Supercomputers, Uncensored Models and Agentic
- Bloomberg reports XBOW, an autonomous AI pentester, ranked #1 on the HackerOne US leaderboard (~1,060 submissions), cited by Netlas as evidence of autonomous offense speed
- HexStrike-AI MCP server (150+ tools, MIT licence) released on GitHub in approximately August 2025; ~1,800 stars and 400+ forks within its first month
- Within ~12 hours of the advisory, underground-forum actors discuss pointing HexStrike-AI at the NetScaler flaws, claiming webshell drops, mass scanning and sale of vulnerable instances (per Check Point)
- Citrix discloses and patches CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424 in NetScaler ADC/Gateway; CVE-2025-7775 confirmed exploited in the wild and added to CISA KEV the same day
- CISA KEV federal remediation deadline for CVE-2025-7775
- Check Point Research publishes HexStrike-AI analysis; Shadowserver counts ~8,000 endpoints still vulnerable to CVE-2025-7775, down from ~28,000 the previous week
- Mid-September 2025: Anthropic detects GTG-1002 using Claude Code with MCP-connected tools against ~30 targets, followed by a ten-day investigation and account bans
- Anthropic publishes its report on the first reported AI-orchestrated cyber espionage campaign, assessing with high confidence a Chinese state-sponsored actor
- Alice research (April 2026) reports abliteration raises harmful-prompt compliance from 5.8% to 98% across 5 models and 110 adversarial prompts
- Netlas publishes analysis tying DGX Spark-class hardware, abliterated models and MCP agent frameworks to automated large-scale attacks
Sources cited for Desktop AI Supercomputers, Uncensored Models and Agentic
- Desktop AI Supercomputers and Automated Attacks (Netlas)
- Check Point: HexStrike-AI - When LLMs Meet Zero-Day Exploitation
- BleepingComputer: Hackers use new HexStrike-AI tool to rapidly exploit n-day flaws
- Infosecurity Magazine: Threat Actors Use HexStrike-AI
- Anthropic: Disrupting the first reported AI-orchestrated cyber espionage campaign
- HexStrike AI MCP Agents repository
- Wiz Vulnerability Database: CVE-2025-7775
- NVD: CVE-2025-7775
- CISA Known Exploited Vulnerabilities Catalog
- Alice abliteration report (April 2026)
- XBOW: Top 1 - how XBOW did it
- Hugging Face: Uncensor any LLM with abliteration
Detection coverage for TL-2026-2881
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2881 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.