Monday, September 7, 2026

Chinese-Speaking Hacker Uses DeepSeek Agent to Launch Autonomous Cyberattacks

Chinese-speaking threat actor “knaithe” (aka KnYuan) has been caught running an AI-enabled autonomous attack stack built around DeepSeek and the Hermes Agent framework, proving that large language models can now drive end‑to‑end offensive operations with minimal human oversight.

Hermes provided terminal access, skills orchestration, and Model Context Protocol (MCP) integrations. At the same time, DeepSeek generated FOFA queries, assessed CVEs, selected targets, and adapted exploit logic.

Parallel to this core stack, the actor experimented with multiple LLMs including Qwen, GLM, Kimi, and MiniMax, alongside limited trials of Western tools such as Claude Code and OpenAI’s Codex, indicating an ongoing evaluation of the AI market for offensive workflows.

The exposed environment showed four AI coding tools configured with loosened local safeguards and routed through anonymizing infrastructure. Claude Code and Codex were tunneled via the code.newcli[.]com proxy to reduce traceability, while DeepSeek and Qwen were hit directly over native APIs.

The actor enabled aggressive anti-attribution flags turning off nonessential traffic and response storage, and allowing dangerous, auto‑approved tool execution (“approvalMode: yolo”).

Hermes Agent itself ran without a built‑in safety layer, bundling a jailbreaking “godmode” skill plus custom exploitation skills, including unauthenticated WebSocket abuse and FOFA‑driven cyberspace search, backed by an MCP server that exposed FOFA asset search and Nuclei scan generation.

The campaign combined autonomous reconnaissance with both failed and successful exploitation across seven vulnerabilities.

DeepSeek first targeted Langflow via CVE‑2026‑33017 (CVSS 9.8), autonomously pulling PoC code from GitHub, enumerating 84 Langflow instances via FOFA, and scanning them, but failing due to missing auto_login and public flow IDs.

It then pivoted, surveying 10 product families and selecting n8n workflow automation as a higher‑value candidate, chaining CVE‑2026‑21858 (arbitrary file read, CVSS 10.0) with CVE‑2025‑68613 (sandbox bypass to RCE, CVSS 9.9).

Despite identifying vulnerable versions and probing Chinese n8n instances, exploitation was blocked by authenticated form requirements, underscoring how defensive configuration alone prevented an otherwise viable autonomous chain.

Unit 42 Researchers said that, the actor wired DeepSeek into Hermes Agent as a primary “reasoning” brain, orchestrated via Telegram for target enumeration, exploit sourcing, and non‑interactive attack execution.

In parallel, the actor ran conventional manual campaigns against perimeter technologies, achieving confirmed impact via Citrix NetScaler (CVE‑2026‑3055), Apache Tomcat (CVE‑2026‑34486), Marimo Notebook (CVE‑2026‑39987), Windows IKE VPN (CVE‑2026‑33824), and non‑functional research around PAN‑OS CVE‑2026‑0300.

Hacker Uses DeepSeek Agent

Across roughly 460 attempted targets, Unit 42 confirmed only three successful compromises, all involving memory data exfiltration from Citrix NetScaler and suspected session hijacking attempts against a Malaysian government entity.

Autonomous attack flow observed in Hermes Agent session (Source : Unit42).
 Autonomous attack flow observed in Hermes Agent session (Source : Unit42).

The entire operation was inadvertently exposed when Hermes Agent, responding to a Telegram command, launched an HTTP file server from /home/worker instead of a sandboxed directory.

This mistake revealed AI tool configurations, exploit scripts, target lists, session logs, and API keys, giving defenders a rare full view of an active AI offensive environment.

Artifact analysis and GitHub activity tied the actor to Zhuhai, China, where they operate as an opportunistic exploit operator and “binary security researcher,” maintaining a 1DayNews vulnerability intelligence pipeline.

Unit 42 concludes that AI‑driven autonomous attack cycles are no longer theoretical: DeepSeek, Hermes Agent, and associated LLM tooling collectively compressed hundreds of hours of manual targeting into minutes.

Palo Alto Networks points to Cortex XDR/XSIAM, Cortex Xpanse, and NGFW with Advanced Threat Prevention as primary controls for detecting and disrupting such campaigns, alongside specialized Unit 42 AI Security Assessment and Frontier AI Defense services for organizations concerned about AI‑enabled risks.

This incident aligns with broader reporting on Chinese operators weaponizing DeepSeek and Claude Code against government and financial networks, and feeds into Unit 42’s ongoing GenAI, LLM, and vulnerability research stream, which is rapidly reframing how defenders must think about AI‑native threat surfaces.

$1M Data Breach Warranty is Genuine Protection?: Download 10 Point Free AI SOC Breach Warranty Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging...

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded...

Related Articles

Recent News