Unit 42: Chinese attacker used DeepSeek AI to autonomously hit 460 sys
# Chinese Threat Actor Weaponized DeepSeek for Autonomous Hacking Campaign
A threat actor operating under the aliases "knaithe" and "KnYuan" deployed DeepSeek through the Hermes Agent framework to orchestrate an autonomous cyberattack campaign targeting more than 460 internet-facing systems, according to Palo Alto Networks' Unit 42. The attacker, based in Zhuhai, China, coordinated the offensive operations via Telegram and combined AI-driven enumeration with manual exploitation to achieve initial access.
Unit 42's investigation found that the campaign leveraged DeepSeek via the Hermes Agent framework as their autonomous offensive operator, marking one of the first documented instances of a large-scale autonomous AI-driven intrusion campaign. The actor targeted infrastructure by exploiting seven vulnerabilities, with confirmed impact from manual exploitation phases following the autonomous scanning and probing stages, according to Forbes.
How the Attack Worked
The campaign combined two operational layers. First, DeepSeek running inside Hermes Agent performed autonomous reconnaissance—scanning target networks, enumerating services, and identifying vulnerable systems at scale. The attacker then used human-directed exploitation to gain access where the AI-driven phase succeeded. This hybrid approach allowed one operator to coordinate probing of 460+ targets with minimal manual effort, while preserving human control over high-value exploitation attempts.
The threat actor maintained command-and-control through Telegram, using the messaging platform to receive updates, adjust targeting parameters, and coordinate timing across the distributed campaign.
Scope and Impact
While Unit 42 confirmed that the campaign targeted more than 460 systems and exploited seven vulnerabilities, some reporting suggested 14 successful intrusions were achieved against already-patched infrastructure. The reliance on already-patched vulnerabilities indicates the actor was targeting systems where defenders had failed to apply available security updates—a persistent friction point in enterprise environments.
The scale of this campaign demonstrates that autonomous agents paired with LLMs can amplify attacker efficiency. A single human operator, guided by an AI system running continuous exploitation loops, can maintain pressure across hundreds of targets simultaneously—a capability that would have required significantly larger teams just two years ago.
Implications for Agent Security
This incident marks a watershed moment for the agent economy: autonomous tools built for legitimate software development, research, and business operations are now documented in offensive use. The distinction between a beneficial agent framework and a weaponized one lies not in the technology itself but in the operator's intent and the safeguards deployed around model access and agent execution.
Security teams and infrastructure operators should assume that AI-driven reconnaissance and exploitation will become standard in advanced threat campaigns, and that patching velocity and security hygiene remain the primary defensive levers against such autonomous threats.