Chinese-Speaking Actor Uses DeepSeek and Hermes Agent for Autonomous Cyberattacks

Share:

Palo Alto Networks Unit 42 has documented a hacker who used artificial intelligence to run
cyberattacks on autopilot. Using the Chinese AI model DeepSeek inside an automation framework, the
attacker had the AI find vulnerable systems, choose which flaws to exploit, and launch attacks on its
own across seven security flaws in widely used software. The fully automated attacks were stopped by
security settings on the target systems, but the attacker’s hands-on efforts still stole data from three
organisations and ran commands on eleven more, a warning that AI-driven attacks are becoming
practical.

1. Campaign Overview

Unit 42 gained rare visibility into this operation after the attacker’s AI agent accidentally started a web server in its home directory, exposing its configuration files, API keys, exploit scripts, and session logs. The actor, a Chinese-speaking opportunistic operator using the aliases knaithe and KnYuan and based in Zhuhai, ran DeepSeek through the open source Hermes Agent framework as an autonomous attack operator controlled over Telegram. Western tools were tested only for connectivity and routed through an anti-attribution proxy. OpenAI confirmed its safeguards refused the actor’s requests and disabled a linked account.

2. Attack Details

AI orchestration

The actor paired DeepSeek, chosen for its minimal safety controls, with the Hermes Agent framework for terminal access, Telegram command and control, and a skills system. Custom skills added an LLM jailbreak (godmode), WebSocket exploitation, and FOFA internet-wide asset search through an MCP server.

Autonomous enumeration and pivot

DeepSeek independently enumerated exposed systems with FOFA, searched GitHub for trending 2026 proof-of concept exploits, and ranked candidates by severity and deployment size. When Langflow (CVE-2026-33017) proved low value, it pivoted on its own to n8n (CVE-2026-21858 and CVE-2025-68613).

Autonomous exploitation (failed)

The agent downloaded public exploits and attacked automatically, but both autonomous targets held: Langflow needed auto_login or a public flow ID, and the vulnerable n8n instances required authenticated form endpoints. No autonomous compromise succeeded.

Manual exploitation (confirmed)

Working by hand, the actor exfiltrated memory from three Citrix NetScaler servers (CVE-2026-3055), hunting NSC_AAAC session cookies, and ran commands on eleven Marimo notebooks (CVE-2026-39987). They also attempted reverse shells against Apache Tomcat (CVE-2026-34486) and Windows IKE VPN (CVE-2026-33824) and staged a non-functional PAN-OS proof of concept (CVE-2026-0300).

3. Payload Capabilities

The actor assembled a reusable AI offensive environment rather than using tools in isolation:

  • Autonomous attack operator: DeepSeek served as the reasoning engine for target selection, code generation, and decision-making, while Hermes Agent supplied terminal access and Telegram control, letting the system discover, assess, pivot, and retarget without human input.
  • Jailbreak and exploitation skills: A framework-bundled godmode skill jailbroke the model, and custom skills handled WebSocket exploitation and FOFA-driven asset enumeration, backed by a FofaMap MCP server that also generated Nuclei scans.
  • Anti-attribution: and model evaluation The actor routed Western tools through the code.newcli[.]com proxy, disabled attribution headers and response logging, and evaluated multiple Chinese LLMs (Qwen, GLM, Kimi, MiniMax), settling on the most permissive model for autonomous attacks.
  • Compute-aware targeting: DeepSeek narrowed roughly 25,000 exposed n8n systems to a small sample it probed directly, running hours of targeting analysis in minutes while managing its own compute budget.

4. Adversary Toolkit

Tool / IndicatorTypeFunction
Hermes AgentAutonomous agent frameworkOpen-source framework providing DeepSeek terminal access, a skills system, and Telegram command-and-control for autonomous attacks.
DeepSeekLLM (reasoning engine)Permissive AI model used for target selection, exploit code generation, and attack decision-making.
FofaMap MCP serverMCP server (FOFA/Nuclei)Exposes FOFA asset search, Nuclei scan generation, and natural-language-to-FOFA translation within the agent.
code.newcli[.]comAnti-attribution proxyThird-party proxy routing Claude Code and Codex traffic to reduce the threat actor’s traceability.

5. Indicators of Compromise (IOCs)

TYPE- INDICATOR
DOMAIN- code.newcli[.]com

6. Recommendations

  • Patch the seven CVEs the actor exploited or staged, prioritising the confirmed-impact ones: Citrix NetScaler CVE-2026-3055, Marimo CVE-2026-39987, and n8n CVE-2026-21858 with CVE-2025-68613 (upgrade to 1.121.0).
  • Remove internet-exposed n8n, Langflow, NetScaler, Marimo, Tomcat, and IKE VPN endpoints from public access or place them behind authentication, since the autonomous attacks failed only where auth or configuration prerequisites were present.
  • For Citrix NetScaler, given the confirmed memory exfiltration, kill and rotate all NetScaler sessions and AAA cookies from a clean state, and hunt for reuse of stolen NSC_AAAC session tokens.
  • Alert on mass FOFA-style scanning and known proof-of-concept exploitation; Palo Alto customers can enable Threat Prevention signatures 97030, 96882, 96855, 97044, 97046, 97251, 97177, and 510019.
  • Block the IOCs at their respective controls.

7. Sources

  • https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
  • https://security.paloaltonetworks.com/CVE-2026-0300
  • https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert