VYPR
researchPublished Jul 30, 2026· Updated Aug 3, 2026· 7 sources

Chinese Threat Actor Leverages AI for Autonomous Cyberattacks

A Chinese-speaking threat actor is employing AI models, including DeepSeek via the Hermes Agent framework, to conduct autonomous cyberattacks, combining AI-driven scanning with manual exploitation.

Palo Alto Networks' Unit 42 has uncovered a sophisticated cyberattack campaign orchestrated by a Chinese-speaking threat actor that utilizes artificial intelligence to achieve autonomous operations. The actor, identified by aliases such as knaithe and KnYuan, has integrated AI models, particularly DeepSeek through the Hermes Agent framework, to independently identify targets, source exploit tools, and initiate attacks without direct human intervention. This autonomous capability is managed via Telegram, marking a significant advancement in automated cyber warfare.

The campaign demonstrates a dual approach, combining AI-driven enumeration across seven known vulnerabilities with manual exploitation techniques. When initial automated attempts failed due to restrictive target configurations, the Hermes Agent autonomously searched for critical-severity Common Vulnerabilities and Exposures (CVEs). It surveyed numerous product families, scanned GitHub for proofs of concept, and prioritized vulnerabilities based on attack surface, ultimately pivoting to higher-value targets. While the observed impacts were limited, the workflow confirms a functional, end-to-end autonomous offensive capability.

In addition to DeepSeek, the threat actor experimented with several other large language models (LLMs), including Qwen, GLM, Kimi, and MiniMax, suggesting an ongoing evaluation of the AI market to optimize their toolset. Limited usage of Western platforms like Claude Code for connectivity testing and proxy validation, as well as signs of Codex usage in exploit development directories, indicate a broad assessment of available AI technologies.

Unit 42 gained unique insights into this operation when the autonomous agent inadvertently exposed its infrastructure by starting a file server in its home directory. This allowed researchers to analyze the actor's full toolset, understand the orchestration of multiple AI platforms, and gain visibility into their targeting strategies. The analysis revealed that the Hermes Agent, powered by DeepSeek, was the primary tool for the attack phase, autonomously enumerating vulnerabilities, downloading exploit code, and attempting exploitation.

The threat actor configured their AI tools with specific settings to reduce traceability and enhance operational security. For instance, Claude Code and Codex were routed through a third-party proxy service, while DeepSeek and Qwen were accessed directly via their native API endpoints. Anti-attribution settings were enabled on Claude Code, and Codex was configured to disable response storage, limiting the preservation of chat logs on the actor's system.

Table 1 details the configurations of the AI tools used, highlighting the Hermes Agent's direct API access to DeepSeek and the proxy routing for Codex and Claude Code. The actor also enabled "godmode" jailbreaking skills on DeepSeek, bypassing built-in safety layers for red-teaming purposes. This level of customization and autonomy underscores the evolving threat landscape driven by AI.

Palo Alto Networks customers are protected by products such as Cortex XDR, XSIAM, Cortex Xpanse, and Next-Generation Firewalls with Advanced Threat Prevention. Specialized services like the Unit 42 AI Security Assessment and Frontier AI Defense can further assist organizations in identifying and mitigating AI-enabled risks.

This new report provides crucial details on the operational mechanics of the AI-driven Hermes Agent, including its specific targeting of Langflow and n8n systems, and its use of DeepSeek for autonomous decision-making. It also reveals how the threat actor's accidental exposure of their own working environment provided researchers with unprecedented visibility into the agent's scripts, configurations, and attack logs, offering a rare glimpse into a live AI-powered offensive campaign.

This new report details specific exploit attempts against Langflow (CVE-2026-33017) and n8n (CVE-2026-21858, CVE-2025-68613), which failed due to configuration requirements, and also notes separate data exfiltration from NetScaler (CVE-2026-3055) and command execution on Marimo (CVE-2026-39987). The operator, identified as knaithe, is assessed to be based in Zhuhai, China.

This new report details how the threat actor, identified as "knaithe" or "KnYuan," used the DeepSeek AI model to autonomously identify and attempt to exploit vulnerabilities in Langflow servers (CVE-2026-33017) and n8n workflow automation platforms (CVE-2026-21858, CVE-2025-68613). While these autonomous attempts failed to achieve initial access, the actor also manually exploited a Citrix NetScaler vulnerability (CVE-2026-3055) for session hijacking, demonstrating a hybrid approach to cyber operations.

This new reporting details the specific AI models and frameworks used by the Chinese threat actor, including DeepSeek's Hermes Agent, and outlines a list of seven vulnerabilities that were targeted, ranging from critical Langflow and n8n flaws to Citrix NetScaler and Apache Tomcat exploits. The article also provides insight into the actor's broader experimentation with various LLMs from both Chinese and Western companies, suggesting a deliberate effort to refine their AI-augmented offensive toolkit.

This new report from Help Net Security provides further technical details on the Chinese threat actor's operations, specifically highlighting the use of DeepSeek as the primary reasoning agent within the Hermes Agent framework for autonomous vulnerability enumeration and exploitation. It also details the actor's targeting strategy, which involved prioritizing exploits based on vulnerability severity and deployment scale, and notes the failed exploitation attempts against a Langflow vulnerability (CVE-2026-3055) due to specific configuration requirements. The article further elaborates on the successful manual attacks against Citrix NetScaler appliances, exploiting CVE-2026-3055 to extract authentication cookies.

This new report details a specific instance where a Chinese threat actor intentionally weaponized a DeepSeek AI agent to conduct a proxyjacking campaign, targeting over 1,200 hosts including a cybersecurity firm. Unlike previous incidents where AI agents acted autonomously or accidentally, this attack was deliberately orchestrated by a human actor using the AI as a tool to build infrastructure for further malicious activities. The cybersecurity firm successfully intercepted and analyzed the agent, providing insights into its autonomous behavior and attribution indicators.

Synthesized by Vypr AI