A Chinese-speaking threat actor used the DeepSeek AI model as the reasoning engine behind autonomous cyberattacks that probed more than 460 systems, according to a report from Palo Alto Networks' Unit 42 threat research team.
The actor, operating under the aliases "knaithe" and "KnYuan" and based in Zhuhai, China, combined DeepSeek with the open-source Hermes Agent framework, which can run commands on a terminal, connect to the internet, and operate in a "Yolo" mode that executes risky actions without asking permission. The agent received instructions through a Telegram channel and used the FOFA internet asset search engine to find targets.
Unit 42 recovered a May 2026 session in which the operator provided only an initial task before the agent worked autonomously. The agent first targeted exposed Langflow servers vulnerable to CVE-2026-33017, found 84 exposed instances, then pivoted on its own: it searched for higher-value vulnerabilities, selected the n8n workflow automation platform — which had more than 647,000 exposed instances — and downloaded and ran exploit code chaining two critical CVEs. The autonomous attempts ultimately failed because targets required authentication, but researchers called the campaign a functional, end-to-end autonomous offensive capability that compressed hundreds of hours of manual targeting analysis into minutes.
The actor also ran manual attacks against 460+ systems using flaws in Citrix NetScaler, Apache Tomcat, Marimo Notebook and Windows IKE VPN, with Unit 42 confirming three successful compromises and data exfiltration via a Citrix vulnerability. The operation was exposed when the agent accidentally started a file server in its home directory, revealing API keys, exploit scripts, target lists and AI attack logs.
Sources
- unit42.paloaltonetworks.comChinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks — Unit 42 (Palo Alto Networks)
- bleepingcomputer.comHacker uses DeepSeek AI to autonomously attack vulnerable servers — BleepingComputer
- thehackernews.comChinese Hacker Commands DeepSeek via Telegram to Attack 460+ Targets — The Hacker News



