Skip to content
DeepSeek AI Used in Autonomous Cyberattack Campaign by Chinese Threat Actor

DeepSeek AI Used in Autonomous Cyberattack Campaign by Chinese Threat Actor

First seen 2 Aug 2026, 08:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 3, 2026 at 06:03 UTC
  • The campaign involved over 460 attempted attacks using DeepSeek AI and Hermes Agent.
  • Only three successful compromises were confirmed, primarily involving data exfiltration from Citrix NetScaler.
  • OpenAI's safety controls effectively blocked the threat actor's attempts to use their models for offensive tasks.

A Chinese-speaking threat actor, identified as knaithe/KnYuan, executed an autonomous cyberattack campaign using DeepSeek AI and the Hermes Agent framework. The campaign targeted over 460 servers, attempting to exploit multiple vulnerabilities, including CVE-2026-33017 and CVE-2026-21858. The attacks were conducted with minimal human intervention, as the AI autonomously handled target enumeration and exploit execution. Although the campaign did not successfully compromise most targets, it marks a significant shift in offensive cyber operations, showcasing the potential of AI in autonomous hacking. The operation was exposed when Hermes accidentally launched a public HTTP server, leaking sensitive information. Unit 42 confirmed that safety controls from OpenAI and Claude Code effectively blocked the actor's attempts to use those models, leading to the selection of DeepSeek due to its lack of guardrails. The incident highlights the operational value of AI safety controls in preventing misuse.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 49d ago How this analysis works

Timeline

2025-12-19
CVE-2025-68613 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-07
CVE-2026-21858 published
CVE-2026-21858 was published with a first public proof-of-concept released on 2023-10-12.
Techtimes
2026-03-20
CVE-2026-33017 published
CVE-2026-33017, a critical vulnerability, was published and later added to CISA KEV for active exploitation.
Techtimes
2026-03-30
CVE-2026-3055 added to CISA KEV
CVE-2026-3055 was added to CISA KEV for active exploitation, highlighting its critical nature.
Oodaloop
2026-04-09
CVE-2026-39987 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-01
Unit 42 publishes findings on the campaign
Palo Alto Networks' Unit 42 published a report detailing the autonomous cyberattack campaign and its implications.
Techtimes
Recent
Campaign exposed via accidental HTTP server launch
The Hermes Agent accidentally launched a public HTTP server, leaking API keys and logs, revealing the campaign's details.
Forkast.News

More articles in this cluster (15)

Following this threat?

Track Knaithe, OpenAI and CVE-2025-68613 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed