Forkast.News
DeepSeek AI Used in Autonomous Cyberattack Campaign by Chinese Threat Actor
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A Chinese-speaking threat actor, identified as knaithe/KnYuan, executed an autonomous cyberattack campaign using DeepSeek AI and the Hermes Agent framework. The campaign targeted over 460 servers, attempting to exploit multiple vulnerabilities, including CVE-2026-33017 and CVE-2026-21858. The attacks were conducted with minimal human intervention, as the AI autonomously handled target enumeration and exploit execution. Although the campaign did not successfully compromise most targets, it marks a significant shift in offensive cyber operations, showcasing the potential of AI in autonomous hacking. The operation was exposed when Hermes accidentally launched a public HTTP server, leaking sensitive information. Unit 42 confirmed that safety controls from OpenAI and Claude Code effectively blocked the actor's attempts to use those models, leading to the selection of DeepSeek due to its lack of guardrails. The incident highlights the operational value of AI safety controls in preventing misuse.
Key Points: • The campaign involved over 460 attempted attacks using DeepSeek AI and Hermes Agent. • Only three successful compromises were confirmed, primarily involving data exfiltration from Citrix NetScaler. • OpenAI's safety controls effectively blocked the threat actor's attempts to use their models for offensive tasks.