VỮNG MÃI MỘT NIỀM TIN

🚨 CyberStrikeAI Identified – AI Platform Behind Large-Scale FortiGate Scanning Campaign Across 55 Countries

  • 09/03/2026

A recent analysis from the international cybersecurity community has revealed new details about the scale and operational methods behind the attack campaign targeting FortiGate devices that was first reported in February 2026. According to the findings, the campaign—which compromised more than 600 devices across 55 countries—may have been coordinated using an automated attack platform known as CyberStrikeAI.

This discovery highlights a growing trend in modern cyberattacks: threat actors are no longer relying solely on generative AI to assist with code development, but are increasingly leveraging AI-integrated attack frameworks to automate reconnaissance, exploitation, and data analysis on a large scale.

CyberStrikeAI – A “Central Control Panel” for Attack Campaigns

CyberStrikeAI is described as an open-source offensive security platform developed in the Go programming language and published on GitHub by a user known as “Ed1s0nZ”.

Technically, it is not a single tool but a framework integrating more than 100 security utilities, designed to simulate attack scenarios and assess the security posture of systems.

(Insert image: CyberStrikeAI interface or architecture diagram)

Key capabilities of the platform include:

  • Large-scale scanning of IP addresses and internet-exposed services to quickly identify potential attack surfaces

  • Attack chain analysis to simulate how an adversary can move from initial access to deeper system control

  • Collection, normalization, and aggregation of technical data for vulnerability assessment and reporting

  • Visualization of scanning and analysis results to prioritize targets during testing or exploitation

In legitimate research environments, such platforms are commonly used for security assessments and penetration testing. However, when misused, their automation and centralized orchestration capabilities can enable attackers to expand the scale of operations within a very short time.

CyberStrikeAI’s Role in the FortiGate Targeting Campaign

Earlier reports indicated that a Russian-speaking threat group exploited internet-exposed FortiGate management interfaces, performing brute-force attacks to obtain login credentials and later moving laterally within affected networks.

New analysis now suggests that the large-scale scanning and target identification phase was likely conducted using CyberStrikeAI.

Observed data indicates that:

  • At least 21 IP addresses were operating the platform

  • Activity occurred between late January and late February 2026

  • Targets were distributed across 55 countries

These findings suggest the campaign went beyond simple AI-assisted coding. Instead, attackers appear to have leveraged a fully integrated, AI-enabled offensive tool ecosystem to accelerate the speed and scope of their operations.

Possible Links to a Broader Offensive Tool Ecosystem

The developer behind CyberStrikeAI is suspected to have possible connections to Knownsec 404, a Chinese cybersecurity company that previously experienced internal document leaks.

At present, there is no confirmed evidence that the FortiGate campaign was tied to any geopolitical objectives. Nevertheless, the origin and development background of the tool are being closely monitored by the global cybersecurity community.

How AI Is Changing the Scale of Cyber Attacks

This case illustrates that artificial intelligence does not necessarily introduce entirely new intrusion techniques. Instead, AI is significantly increasing the speed and scale at which existing attack methods can be executed.

Tasks such as:

  • Large-scale internet scanning

  • Credential brute-force attempts

  • System configuration analysis

  • Target data aggregation

previously required substantial time and human resources. Today, they can be automated and centrally coordinated through integrated AI-enabled frameworks.

As a result, even moderately skilled threat actors may now be capable of launching global-scale attack campaigns if target systems contain basic security weaknesses.

Security Recommendations for FortiGate Deployments

For organizations and agencies in Vietnam currently operating FortiGate devices, the greatest risks often stem not from sophisticated zero-day vulnerabilities but from common security management issues.

DTG recommends organizations review and implement the following measures:

  • Avoid exposing FortiGate administrative interfaces directly to the internet

  • Enable multi-factor authentication (MFA) for administrative accounts

  • Prevent password reuse and enforce strong password policies

  • Implement monitoring systems to detect abnormal access behavior

  • Regularly update firmware and apply security patches

As network infrastructures continue to expand and become more distributed, packaged attack tools enhanced with AI can quickly amplify minor configuration errors into widespread security incidents. Therefore, configuration management, access control, and continuous security monitoring should be treated as foundational defenses rather than relying solely on protection against advanced attack scenarios.


Partner