News thumbnail
Technology / Sat, 22 Aug 2026 cyberpress.org

Chinese Hacker Uses DeepSeek AI to Automate Vulnerability Exploitation

Chinese Hacker Uses DeepSeek AIThe actor primarily used DeepSeek through the open-source Hermes Agent framework, which supplied terminal access, a skill system, and Telegram-based command-and-control capabilities. DeepSeek acted as the reasoning engine, making decisions about target selection, code generation, vulnerability assessment, and follow-on actions. In one recovered Hermes Agent session from May 2026, DeepSeek first targeted a critical Langflow vulnerability tracked as CVE-2026-33017. Although the autonomous DeepSeek operations did not result in a confirmed compromise, Unit 42 identified separate manual campaigns by the same actor that achieved impact. Ironically, Hermes Agent exposed the attacker’s infrastructure by launching a Python HTTP server from the operator’s home directory rather than an isolated staging folder.

A Chinese-speaking threat actor has been observed using DeepSeek AI as an autonomous offensive operator to identify exposed infrastructure, research vulnerabilities, acquire public proof-of-concept exploits, and launch attacks with minimal human intervention.

Palo Alto Networks Unit 42 tracked the activity to an actor known as knaithe and KnYuan, describing the campaign as an early but functional example of end-to-end AI-assisted cyberattack automation.

While the autonomous operations produced limited confirmed impact, the researchers warned that the campaign demonstrates how large language models can accelerate vulnerability research, target prioritization, and exploitation workflows.

Chinese Hacker Uses DeepSeek AI

The actor primarily used DeepSeek through the open-source Hermes Agent framework, which supplied terminal access, a skill system, and Telegram-based command-and-control capabilities.

DeepSeek acted as the reasoning engine, making decisions about target selection, code generation, vulnerability assessment, and follow-on actions.

The threat actor customized Hermes Agent with red-teaming capabilities, including a “godmode” jailbreak feature, an unauthenticated WebSocket exploitation workflow, and a FOFA internet asset search tool.

Attack flow (Source: Palo Alto Network)

The environment also integrated an MCP server that enabled FOFA searches, Nuclei scan generation, and natural-language conversion of prompts into FOFA queries.

Investigators found that the actor had also configured Qwen, GLM, Kimi, and MiniMax models, apparently testing several Chinese AI platforms.

Claude Code and Codex were used in a more limited capacity, primarily for connectivity testing, proxy validation, and potential exploit development.

In one recovered Hermes Agent session from May 2026, DeepSeek first targeted a critical Langflow vulnerability tracked as CVE-2026-33017.

The AI downloaded a public exploit, identified 84 exposed Langflow instances through FOFA, and found one potentially vulnerable system.

However, exploitation failed because the target lacked required configuration conditions. DeepSeek then independently assessed Langflow as a low-value opportunity and pivoted to research other high-severity vulnerabilities with a larger attack surface.

The agent surveyed 10 product families, reviewed trending GitHub vulnerability repositories, and ranked targets based on severity, availability of exploit code, and deployment volume.

It ultimately selected n8n, a workflow automation platform, after identifying more than 647,000 internet-exposed instances globally.

DeepSeek obtained a public exploit chain targeting CVE-2026-21858 and CVE-2025-68613, which could enable arbitrary file reading and remote code execution in vulnerable n8n deployments.

It identified several systems running affected versions, but the exploit attempts failed because the required form endpoints were protected by authentication.

Although the autonomous DeepSeek operations did not result in a confirmed compromise, Unit 42 identified separate manual campaigns by the same actor that achieved impact.

The actor reportedly exfiltrated data from three Citrix NetScaler targets through CVE-2026-3055 and executed commands on 11 Marimo notebook instances using CVE-2026-39987.

Additional activity included reverse-shell attempts against Apache Tomcat servers and Windows IKE VPN endpoints.

Palo Alto Networks said the actor targeted more than 460 systems using both automated and manual techniques. In one case, stolen NetScaler memory data was searched for authentication cookies, suggesting possible session-hijacking objectives.

Ironically, Hermes Agent exposed the attacker’s infrastructure by launching a Python HTTP server from the operator’s home directory rather than an isolated staging folder.

This mistake exposed API keys, target lists, exploit scripts, Bash history, and autonomous attack-session logs. The incident highlights a growing security challenge: AI models can now support rapid reconnaissance, vulnerability prioritization, and attack execution.

But it also shows that autonomous tooling may introduce new operational security failures that defenders can exploit to uncover malicious activity.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN

© All Rights Reserved.