Threat reportThreat IntelligenceTL-2026-2881

Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated Large-Scale Attacks, incl. CVE-2025-7775 Citrix NetScaler

highACTIVE

Desktop AI Supercomputers, Uncensored Models and Agentic (TL-2026-2881), also tracked as HexStrike-AI abuse, is a high-severity tracked intrusion set scored CVSS 9.8, first published 2026-10-03. It has no confirmed attribution, affects Citrix / Cloud Software Group NetScaler ADC and NetScaler Gateway, references 3 CVEs (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424), maps to 13 MITRE ATT&CK / ATLAS techniques (AML.T0018, AML.T0053, AML.T0054), and is covered by 9 detection rules and 10 indicators of compromise.

CVSS
9.8/10High
CVEs
3Referenced vulnerabilities
Techniques
13MITRE ATT&CK / ATLAS
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
10Indicators of compromise

Key facts for TL-2026-2881

Threat ID
TL-2026-2881
Also known as
HexStrike-AI abuse, AI-orchestrated automated exploitation, GTG-1002 (referenced context)
Severity
HIGH
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, finance, chemical, government administration, telecoms
Target regions
Global
Detection rules
9
Indicators of compromise
10

Malware and tooling in Desktop AI Supercomputers, Uncensored Models and Agentic

Malware and tooling: Abliterated open-weight LLMs (Hugging Face), Claude Code, FastMCP, Heretic, HexStrike-AI, Nmap, Nuclei

How Desktop AI Supercomputers, Uncensored Models and Agentic works

Netlas reports that affordable local AI hardware (NVIDIA DGX Spark), abliterated open-weight models and MCP-based agentic orchestration are converging to make autonomous, large-scale attacks cheap. Check Point documented threat actors pointing the open-source HexStrike-AI MCP framework at Citrix NetScaler CVE-2025-7775 within 12 hours of disclosure, with claims of exploitation compressed from days to under ten minutes.

Netlas (Bedrettin Ortak, 2026-08-05) argues that three trends now combine: (1) desktop AI hardware such as the NVIDIA DGX Spark (1 petaFLOP FP4, 128 GB unified memory, 4 TB SSD, $4,699 as of August 2026; fine-tuning of models up to ~70B parameters and inference up to ~200B), (2) abliterated open-weight models, where refusal behaviour is removed by editing weights (technique popularised by FailSpy building on Arditi et al. 2024; automated by the Heretic tool; an Alice research study of April 2026 reported harmful-prompt compliance rising from 5.8% to 98% across 5 models after abliteration), and (3) agentic orchestration over the Model Context Protocol (MCP), which lets a language model drive many offensive tools autonomously.

The concrete incident cited is HexStrike-AI, an MIT-licensed open-source MCP server (GitHub 0x4m4/hexstrike-ai, published by Muhammad Osama / OTT Cybersecurity LLC) that exposes 150+ security tools (Nmap, Nuclei with 4,000+ templates, browser automation, cloud assessment, 12+ specialised agents) to MCP-capable clients such as Claude Desktop, VS Code Copilot, Cursor and Roo Code. Check Point Research (2025-09-02) reported that within about 12 hours of Citrix's 2025-08-26 advisory for three NetScaler zero-days (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424), underground-forum actors were discussing using HexStrike-AI against them. Claims included unauthenticated RCE on CVE-2025-7775, webshell deployment for persistence, parallel scanning of thousands of IPs, and sale of compromised/vulnerable instances. The 'under 10 minutes' timing is an actor claim relayed by Check Point, not independently measured.

CVE-2025-7775 is a memory overflow (CWE-119) in NetScaler ADC/Gateway leading to RCE and/or DoS, CVSS v3.1 9.8 / v4.0 9.2, exploitable without authentication on appliances configured as Gateway (VPN vserver, ICA Proxy, CVPN, RDP Proxy), AAA vservers, LB vservers bound to IPv6 services, or CR vservers of type HDX. It was added to CISA KEV on 2025-08-26 (federal due date 2025-08-28). Shadowserver counted ~28,000 exposed endpoints initially and ~8,000 by 2025-09-02.

For context the article also cites GTG-1002, assessed by Anthropic with high confidence as a Chinese state-sponsored group that in mid-September 2025 used Claude Code with MCP-connected scanners and password crackers to run an espionage campaign against ~30 targets (technology, finance, chemical manufacturing, government), with the AI performing an estimated 80-90% of tactical work and humans making 4-6 decision points per campaign. GTG-1002 bypassed safeguards through role-play (posing as defensive testers) and task decomposition, not abliteration; Claude's hallucinated credentials were a limiting factor. XBOW, a legitimate autonomous pentester that topped the HackerOne US leaderboard in June 2025, is cited as evidence of the speed of autonomous offense. There is no single named adversary or new malware in the Netlas article; this record tracks the capability trend and the HexStrike-AI/NetScaler abuse.

MITRE ATT&CK / ATLAS techniques used in TL-2026-2881

Persistence

AML.T0018 Manipulate AI Model; T1505.003 Web Shell

Execution

AML.T0053 AI Agent Tool Invocation; T1059 Command and Scripting Interpreter

Defense Evasion

AML.T0054 LLM Jailbreak

Discovery

T1046 Network Service Discovery

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Credential Access

T1110 Brute Force

Resource Development

T1588.002 Tool; T1588.006 Vulnerabilities; T1588.007 Artificial Intelligence

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in Desktop AI Supercomputers, Uncensored Models and Agentic

  • Citrix / Cloud Software Group — NetScaler ADC and NetScaler Gateway (CVE-2025-7775)
    Vulnerable versions: 13.1 before 13.1-59.22; 14.1 before 14.1-47.48; 12.1-FIPS/NDcPP before 12.1-55.330; 13.1-FIPS/NDcPP before 13.1-37.241
    Fixed in: 13.1-59.22; 14.1-47.48; 12.1-FIPS/NDcPP 12.1-55.330; 13.1-FIPS/NDcPP 13.1-37.241

Remediation for Desktop AI Supercomputers, Uncensored Models and Agentic

Patches

  • NetScaler ADC/Gateway 14.1-47.48 or later
  • NetScaler ADC/Gateway 13.1-59.22 or later
  • NetScaler ADC 13.1-FIPS/NDcPP 13.1-37.241 or later
  • NetScaler ADC 12.1-FIPS/NDcPP 12.1-55.330 or later

Immediate actions

  • Upgrade NetScaler ADC/Gateway to 14.1-47.48+, 13.1-59.22+, 13.1-FIPS/NDcPP 13.1-37.241+ or 12.1-FIPS/NDcPP 12.1-55.330+ and hunt for webshells on appliances that were exposed before patching
  • Inventory NetScaler appliances configured as Gateway, AAA, IPv6 LB or CR/HDX vservers and prioritise them
  • Check CISA KEV for CVE-2025-7775 and meet the same-day patch expectation

Workarounds

  • Reduce exposure of Gateway/AAA virtual servers to the internet until patched
  • Follow vendor mitigations per CISA KEV guidance or discontinue use if mitigations are unavailable

Longer-term hardening

  • Build automated same-day patching and validation pipelines for internet-facing edge devices
  • Continuous external attack-surface discovery
  • Automated detection and response operating at machine speed; behavioural monitoring rather than payload signatures
  • Least-privilege scoping and action logging for internal agent/MCP tools
  • Threat-intelligence monitoring of underground forums for rapid tooling changes

CVEs associated with Desktop AI Supercomputers, Uncensored Models and Agentic

CVE-2025-7775, CVE-2025-7776, CVE-2025-8424

Weaknesses (CWE) in Desktop AI Supercomputers, Uncensored Models and Agentic

CWE-119

Timeline of Desktop AI Supercomputers, Uncensored Models and Agentic

  • Bloomberg reports XBOW, an autonomous AI pentester, ranked #1 on the HackerOne US leaderboard (~1,060 submissions), cited by Netlas as evidence of autonomous offense speed
  • HexStrike-AI MCP server (150+ tools, MIT licence) released on GitHub in approximately August 2025; ~1,800 stars and 400+ forks within its first month
  • Within ~12 hours of the advisory, underground-forum actors discuss pointing HexStrike-AI at the NetScaler flaws, claiming webshell drops, mass scanning and sale of vulnerable instances (per Check Point)
  • Citrix discloses and patches CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424 in NetScaler ADC/Gateway; CVE-2025-7775 confirmed exploited in the wild and added to CISA KEV the same day
  • CISA KEV federal remediation deadline for CVE-2025-7775
  • Check Point Research publishes HexStrike-AI analysis; Shadowserver counts ~8,000 endpoints still vulnerable to CVE-2025-7775, down from ~28,000 the previous week
  • Mid-September 2025: Anthropic detects GTG-1002 using Claude Code with MCP-connected tools against ~30 targets, followed by a ten-day investigation and account bans
  • Anthropic publishes its report on the first reported AI-orchestrated cyber espionage campaign, assessing with high confidence a Chinese state-sponsored actor
  • Alice research (April 2026) reports abliteration raises harmful-prompt compliance from 5.8% to 98% across 5 models and 110 adversarial prompts
  • Netlas publishes analysis tying DGX Spark-class hardware, abliterated models and MCP agent frameworks to automated large-scale attacks

Sources cited for Desktop AI Supercomputers, Uncensored Models and Agentic

Detection coverage for TL-2026-2881

As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2881 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
10 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats