Skip to main content
Emerging ThreatsMalware & Ransomware

Chinese Hacker Exploits DeepSeek AI to Automate Vulnerability Attacks

Modern industrial facility with networking equipment and computer terminal.

“Enabled them to dramatically increase the speed and scale of their campaigns,” said Andy Piazza, summarizing how an open-source agentic AI framework helped a Chinese-speaking actor move from reconnaissance to attempted exploitation.

Hermes Agent, DeepSeek, and autonomous orchestration via Telegram

The intrusions detailed in the July 30 report from Unit 42, Palo Alto Networks’ research team, were orchestrated through Hermes Agent — described in the report as an open-source agentic AI framework — connected to a DeepSeek AI model and operated over Telegram. According to the report, Hermes Agent autonomously scanned and researched targets, searching for known critical-severity common vulnerabilities and exposures (CVEs), scanning GitHub for trending proofs of concept (PoC) exploits, and prioritizing vulnerabilities by attack surface.

The actor: “knaithe” / “KnYuan” of Zhuhai and their tooling

Palo Alto Networks identified the operator as a Chinese-speaking individual using the aliases “knaithe” and “KnYuan,” based in Zhuhai, China. Piazza described them as “an opportunistic exploit operator and self-described binary security researcher,” citing the actor’s GitHub activity and maintenance of 1DayNews, an automated vulnerability intelligence pipeline. The actor combined autonomous AI-driven enumeration and automated exploitation with manual exploitation techniques, and used Hermes Agent as the autonomous operator platform.

Seven prioritized CVEs and how each attempt played out

  • CVE-2026-33017 (CVSS 9.8) — Langflow: autonomous exploitation attempt; failed due to auto_login being disabled.
  • CVE-2026-21858 (CVSS 10.0) — n8n Workflow Automation: autonomous exploitation attempt; failed because authentication was required.
  • CVE-2025-68613 (CVSS 9.9) — n8n Workflow Automation: autonomous exploitation attempt; failed because authentication was required.
  • CVE-2026-3055 (CVSS 9.8) — Citrix NetScaler ADC & Gateway: manual active exploitation; data exfiltrated.
  • CVE-2026-34486 (CVSS 7.5) — Apache Tomcat: manual active exploitation with reverse shell attempts.
  • CVE-2026-39987 (CVSS 9.8) — Marimo Notebook: manual active exploitation; command execution confirmed.
  • CVE-2026-0300 (CVSS 9.8) — PAN-OS User-ID Authentication Portal: manual, non-functional research PoC cloned (not executed).
  • CVE-2026-33824 (CVSS 9.8) — Windows IKE Extensions (IKE VPN): manual active exploitation with reverse shell attempts.

Unit 42’s reporting makes clear that, although several manual exploits produced evidence of activity (including data exfiltration and confirmed command execution), the overall campaign had limited impact and did not achieve full compromise of any intended targets.

Multiple LLMs tested — Chinese models, with limited Western-tool use

In parallel with DeepSeek, the actor configured and evaluated multiple language models. The report lists Chinese LLMs Qwen, GLM, Kimi and MiniMax among those used. The actor also conducted limited usage and testing of Western AI tools: Claude Code was used for connectivity testing and proxy validation, and OpenAI’s Codex was touched for exploit development directories. Piazza wrote, “This limited usage is consistent with evaluating the AI-market to identify their preferred tool set.”

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: expect AI-augmented workflows that combine autonomous enumeration with targeted manual exploitation; the actor “is actively iterating — refining tool configurations, developing custom skills, establishing proxy infrastructure and executing autonomous attack cycles,” Piazza noted.
  • Policymakers and regulators: the report emphasizes trajectory over outcome — “The technical barrier to AI-augmented offensive operations is low and continues to decrease,” the researcher added — a trend the report presents as a strategic concern regardless of this campaign’s limited impact.
  • Affected enterprises and procurement leaders: Unit 42’s findings tie autonomous tooling to the practice of scanning GitHub for trending PoCs and prioritizing by attack surface; the campaign targeted internet-exposed infrastructure across three countries, including China and Malaysia, indicating that internet-facing services and fast-emerging PoCs are focal points for AI-augmented operators.

The Unit 42 report’s principal lesson is procedural rather than purely tactical: the actor’s tools and methods are evolving. As Piazza framed it, the “main takeaway from this campaign lies in the trajectory rather than the outcome.” The incident shows a working, end-to-end autonomous offensive capability in active development — an operational reality that defenders and decision-makers will need to factor into risk assessments even when individual campaigns fall short of complete compromise.

Original reporting: https://www.infosecurity-magazine.com/news/chinese-hacker-deepseek-ai/