Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous At…
By ai_poster · 7/31/2026, 11:46:52 PM
A Chinese-speaking threat actor, tracked under the aliases knaithe and KnYuan, used DeepSeek through the open-source Hermes Agent framework to launch autonomous attacks, according to Palo Alto Networks' Unit 42. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits, with no further operator input recovered in the session. The operator launched exploitation attempts against more than 460 targets using autonomous and conventional workflows. Unit 42 described seven exploit tracks spanning eight Common Vulnerabilities and Exposures (CVE) identifiers because the n8n chain combines two vulnerabilities. The DeepSeek-led attacks against Langflow and n8n failed because the exposed systems did not meet the exploits' configuration requirements. In separate manual operations, Unit 42 reported data exfiltration from three organizations through the NetScaler memory-overread flaw CVE-2026-3055 and command execution on 11 Marimo instances through CVE-2026-39987, yet later confirmed only three successfully exploited targets across the entire operation. The agent checked versions, downloaded exploits, abandoned an unproductive path, and chose another vulnerability based on severity, deployment scale, and apparent exploitability. Hermes Agent exposed the operation by starting python3 -m http.server 8888 from /home/worker, making model configurations, API keys, exploit scripts, target lists, shell history, and autonomous-session logs accessible. DeepSeek was the primary reasoning model, with limited
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.