Chinese Threat Actor Leverages AI for Autonomous Cyberattacks
A Chinese-speaking threat actor is employing AI models, including DeepSeek via the Hermes Agent framework, to conduct autonomous cyberattacks, combining AI-driven scanning with manual exploitation.
Palo Alto Networks' Unit 42 has uncovered a sophisticated cyberattack campaign orchestrated by a Chinese-speaking threat actor that utilizes artificial intelligence to achieve autonomous operations. The actor, identified by aliases such as knaithe and KnYuan, has integrated AI models, particularly DeepSeek through the Hermes Agent framework, to independently identify targets, source exploit tools, and initiate attacks without direct human intervention. This autonomous capability is managed via Telegram, marking a significant advancement in automated cyber warfare.
The campaign demonstrates a dual approach, combining AI-driven enumeration across seven known vulnerabilities with manual exploitation techniques. When initial automated attempts failed due to restrictive target configurations, the Hermes Agent autonomously searched for critical-severity Common Vulnerabilities and Exposures (CVEs). It surveyed numerous product families, scanned GitHub for proofs of concept, and prioritized vulnerabilities based on attack surface, ultimately pivoting to higher-value targets. While the observed impacts were limited, the workflow confirms a functional, end-to-end autonomous offensive capability.
In addition to DeepSeek, the threat actor experimented with several other large language models (LLMs), including Qwen, GLM, Kimi, and MiniMax, suggesting an ongoing evaluation of the AI market to optimize their toolset. Limited usage of Western platforms like Claude Code for connectivity testing and proxy validation, as well as signs of Codex usage in exploit development directories, indicate a broad assessment of available AI technologies.
Unit 42 gained unique insights into this operation when the autonomous agent inadvertently exposed its infrastructure by starting a file server in its home directory. This allowed researchers to analyze the actor's full toolset, understand the orchestration of multiple AI platforms, and gain visibility into their targeting strategies. The analysis revealed that the Hermes Agent, powered by DeepSeek, was the primary tool for the attack phase, autonomously enumerating vulnerabilities, downloading exploit code, and attempting exploitation.
The threat actor configured their AI tools with specific settings to reduce traceability and enhance operational security. For instance, Claude Code and Codex were routed through a third-party proxy service, while DeepSeek and Qwen were accessed directly via their native API endpoints. Anti-attribution settings were enabled on Claude Code, and Codex was configured to disable response storage, limiting the preservation of chat logs on the actor's system.
Table 1 details the configurations of the AI tools used, highlighting the Hermes Agent's direct API access to DeepSeek and the proxy routing for Codex and Claude Code. The actor also enabled "godmode" jailbreaking skills on DeepSeek, bypassing built-in safety layers for red-teaming purposes. This level of customization and autonomy underscores the evolving threat landscape driven by AI.
Palo Alto Networks customers are protected by products such as Cortex XDR, XSIAM, Cortex Xpanse, and Next-Generation Firewalls with Advanced Threat Prevention. Specialized services like the Unit 42 AI Security Assessment and Frontier AI Defense can further assist organizations in identifying and mitigating AI-enabled risks.