Fetching from the wire…
Public story · 2026-02-26 · source-backed
Deep-dive analysis reveals ARXON, a custom Python MCP server used in the FortiGate 600+ device campaign. ARXON ingests reconnaissance data, queries DeepSeek for structured attack plans, and uses Claude Code to autonomously execute Impacket, Metasploit, and hashcat with hardcoded credentials. A Go-based orchestrator (CHECKER2) processed 2,516 targets in parallel across 106 countries. This is the first publicly documented case of MCP being used as offensive attack infrastructure, evolved from the open-source HexStrike framework. HexStrike v6.0 was separately exploited to weaponize Citrix CVE-2025-7775 in under 10 minutes.
The MCP protocol that powers your legitimate agent tooling is equally effective for autonomous attack campaigns. The 37% of network-exposed MCP servers with zero authentication makes this an active, exploitable attack surface.
Each link below shares sources, entities, or timing with this story.
ARXON uses CHECKER2 / Shared entities / Shared topic / What happened next
Linked by a graph relationship (ARXON uses CHECKER2); both cover ARXON, DeepSeek, MCP; overlapping topics (active, agent, arxon, attack, campaign).
Windsurf uses MCP / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (Windsurf uses MCP); both cover Claude Code, MCP; overlapping topics (agent, attack, claude, code, server).
ARXON uses CHECKER2 / Shared entities / Same source / Shared topic / Tension
Linked by a graph relationship (ARXON uses CHECKER2); both cover ARXON, MCP; cite the same source (Deep-dive analysis).
Claude Code uses MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Claude Code uses MCP); both cover Claude Code, DeepSeek, MCP; overlapping topics (agent, claude, code).
Anthropic released MCP / Shared entity: MCP / Same source domain / Shared topic / What happened next / Tension
Linked by a graph relationship (Anthropic released MCP); both cover MCP; reported by the same outlet (dev.to).
Claude Code uses MCP / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (Claude Code uses MCP); both cover Claude Code, MCP; overlapping topics (active, agent, claude, code).
Cursor uses MCP / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (Cursor uses MCP); both cover Claude Code, MCP; overlapping topics (agent, claude, code, server).
Anthropic released MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Anthropic released MCP); both cover Claude Code, MCP; overlapping topics (attack, claude, code, credential, documented).