Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

unit42.paloaltonetworks+1cyberpressunit42.paloaltonetworksA Chinese-speaking threat actor used DeepSeek as the reasoning engine for an autonomous hacking system that scanned more than 460 targets and successfully compromised at least three organizations, according to research published by Palo Alto Networks Unit 42 on July 29.unit42.paloaltonetworks
The operation was discovered only because the AI agent itself made a mistake — launching a public file server from the attacker's home directory and exposing the entire operational environment to researchers.
The actor, operating under the aliases "knaithe" and "KnYuan," deployed DeepSeek within the open-source Hermes Agent framework, issuing commands through Telegram and then leaving the system to operate without further human input. The agent independently enumerated internet-facing targets using the FOFA search engine, downloaded public exploit code from GitHub, and attempted exploitation — all without continuous oversight.thehackernews+1
In a recovered session from May 2026, the agent first targeted a Langflow vulnerability (CVE-2026-33017) but abandoned the effort after determining that all 84 identified instances lacked the required configuration for exploitation. It then autonomously surveyed 10 product families, searched GitHub for trending proof-of-concept exploits, and pivoted to n8n workflow automation software, targeting a chain combining CVE-2026-21858 and CVE-2025-68613. Despite finding over 25,000 exposed n8n instances in China, all required authentication, and no compromise was achieved through the autonomous workflow.unit42.paloaltonetworks+1
Separate manual campaigns by the same actor achieved confirmed data exfiltration from three organizations via a Citrix NetScaler vulnerability (CVE-2026-3055), including persistent targeting of a Malaysian government entity over multiple days.unit42.paloaltonetworks
Beyond DeepSeek, the actor configured multiple Chinese-market LLMs including Qwen, GLM, Kimi, and MiniMax. Limited use of Western tools — Claude Code for connectivity testing and signs of Codex in exploit development directories — was also observed. The actor routed Western tools through proxy infrastructure and disabled logging features to reduce traceability.cyberpress+1
Unit 42 noted that DeepSeek was likely chosen because of its minimal safety controls, accessed through a framework with no client-side restrictions. OpenAI confirmed to Unit 42 that its provider-side safeguards refused policy-violating requests and flagged an account believed linked to the campaign.unit42.paloaltonetworks
The irony of the case is that the automation designed to scale attacks ultimately exposed the operation. When Hermes Agent executed `python3 -m http.server 8888` from the actor's working directory, it made API keys, exploit scripts, target lists, and session logs publicly accessible.thehackernews+1
"The significance of these findings lies in the trajectory rather than the outcome of any individual campaign," Unit 42 wrote. "The technical barrier to AI-augmented offensive operations is low and continues to decrease".unit42.paloaltonetworks
Unit 42 assessed the operator to be based in Zhuhai, China, describing them as an opportunistic exploit operator and self-described binary security researcher. The researchers recommended immediate patching of affected Langflow, n8n, Marimo, and NetScaler systems and restricting unnecessary public access to workflow interfaces.thehackernews+1