Unit 42 researchers uncovered a Chinese-speaking threat actor (aliases: knaithe, KnYuan) running an AI-enabled autonomous hacking campaign using DeepSeek via the Hermes Agent framework, orchestrated through Telegram. The actor autonomously enumerated targets, searched for CVE PoCs on GitHub, downloaded exploit code, and attempted exploitation against seven vulnerabilities — all without human intervention. The autonomous cycle included pivoting from failed Langflow exploitation to n8n after DeepSeek independently assessed target value and attack surface. The actor also tested Claude Code, Codex, and Qwen Code, routing Western tools through a proxy to reduce traceability. Ironically, the autonomous agent exposed the entire operation by starting an HTTP file server from the home directory, revealing API keys, exploit scripts, and session logs. Manual campaigns separately achieved confirmed impact: data exfiltration from three organizations via a Citrix NetScaler vulnerability, command execution on Marimo notebook instances, and reverse shell attempts against Apache Tomcat and IKE VPN endpoints. The findings confirm that end-to-end autonomous offensive AI capability is operationally viable, with failure margins determined by target-side configuration rather than the AI's limitations.

14m read timeFrom unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryTechnical AnalysisManual CampaignsHow the AI Exposed the OperationVulnerabilitiesTargeting Analysis and Limited SuccessAttributionConclusionPalo Alto Networks Protection and MitigationAdditional Resources
63 Impressions