<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/chinese-speaking-threat-actor-harnesses-ai-models-for-autonomous-cyberattacks-9nzq2uolr" -->

---
title: Chinese-Speaking Threat Actor Harnesses AI Models for...
description: Unit 42 researchers uncovered a Chinese-speaking threat actor (aliases: knaithe, KnYuan) running an AI-enabled autonomous hacking campaign using DeepSeek via...
canonical: https://daily.dev/posts/chinese-speaking-threat-actor-harnesses-ai-models-for-autonomous-cyberattacks-9nzq2uolr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks | daily.dev
og:description: Unit 42 researchers uncovered a Chinese-speaking threat actor (aliases: knaithe, KnYuan) running an AI-enabled autonomous hacking campaign using DeepSeek via...
og:url: https://daily.dev/posts/chinese-speaking-threat-actor-harnesses-ai-models-for-autonomous-cyberattacks-9nzq2uolr
og:image: https://api.daily.dev/og/posts/9nzQ2UOLr.png
og:image:alt: Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

**[Unit 42](https://daily.dev/sources/unit42)** · 14 min read · 0 upvotes · 0 comments

## Summary

Unit 42 researchers uncovered a Chinese-speaking threat actor (aliases: knaithe, KnYuan) running an AI-enabled autonomous hacking campaign using DeepSeek via the Hermes Agent framework, orchestrated through Telegram. The actor autonomously enumerated targets, searched for CVE PoCs on GitHub, downloaded exploit code, and attempted exploitation against seven vulnerabilities — all without human intervention. The autonomous cycle included pivoting from failed Langflow exploitation to n8n after DeepSeek independently assessed target value and attack surface. The actor also tested Claude Code, Codex, and Qwen Code, routing Western tools through a proxy to reduce traceability. Ironically, the autonomous agent exposed the entire operation by starting an HTTP file server from the home directory, revealing API keys, exploit scripts, and session logs. Manual campaigns separately achieved confirmed impact: data exfiltration from three organizations via a Citrix NetScaler vulnerability, command execution on Marimo notebook instances, and reverse shell attempts against Apache Tomcat and IKE VPN endpoints. The findings confirm that end-to-end autonomous offensive AI capability is operationally viable, with failure margins determined by target-side configuration rather than the AI's limitations.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign>

## Similar posts on daily.dev

- [Hacker uses DeepSeek AI to autonomously attack vulnerable servers](https://daily.dev/posts/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers-b4dqtodah) · BleepingComputer · 0 upvotes · 0 comments
- [Chinese Actor Weaponizes DeepSeek AI Agent Against Security Firm](https://daily.dev/posts/chinese-actor-weaponizes-deepseek-ai-agent-against-security-firm-htf1hk6en) · Dark Reading · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#deepseek](https://daily.dev/tags/deepseek)

[View this post on daily.dev](https://daily.dev/posts/chinese-speaking-threat-actor-harnesses-ai-models-for-autonomous-cyberattacks-9nzq2uolr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks","url":"https://daily.dev/posts/chinese-speaking-threat-actor-harnesses-ai-models-for-autonomous-cyberattacks-9nzq2uolr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/chinese-speaking-threat-actor-harnesses-ai-models-for-autonomous-cyberattacks-9nzq2uolr"},"datePublished":"2026-07-30T10:05:32.925Z","dateModified":"2026-07-30T10:06:01.139Z","description":"Unit 42 researchers uncovered a Chinese-speaking threat actor (aliases: knaithe, KnYuan) running an AI-enabled autonomous hacking campaign using DeepSeek via...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d450968f7c0142cede214a5d2cff36c5?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d450968f7c0142cede214a5d2cff36c5?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Unit 42","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Unit 42","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/5b55ca8d2ae04181939041fbc9d78160","url":"https://daily.dev/sources/unit42"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/chinese-speaking-threat-actor-harnesses-ai-models-for-autonomous-cyberattacks-9nzq2uolr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,deepseek","timeRequired":"PT14M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Unit 42","item":"https://daily.dev/sources/unit42"},{"@type":"ListItem","position":3,"name":"Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks"}]}
```

