DeepSeek AI Used in Autonomous Cyberattack Campaign by Chinese Threat Actor

DeepSeek AI Used in Autonomous Cyberattack Campaign by Chinese Threat Actor

First seen 2 Aug 2026, 08:53 UTC OodaloopTechtimesAiweekly.CoForkast.Newswww.bleepingcomputer.com+1 79% similarity 59.6

Article Content

Browse articles
ThreatCluster

A Chinese-speaking threat actor, identified as knaithe/KnYuan, executed an autonomous cyberattack campaign using DeepSeek AI and the Hermes Agent framework. The campaign targeted over 460 servers, attempting to exploit multiple vulnerabilities, including CVE-2026-33017 and CVE-2026-21858. The attacks were conducted with minimal human intervention, as the AI autonomously handled target enumeration and exploit execution. Although the campaign did not successfully compromise most targets, it marks a significant shift in offensive cyber operations, showcasing the potential of AI in autonomous hacking. The operation was exposed when Hermes accidentally launched a public HTTP server, leaking sensitive information. Unit 42 confirmed that safety controls from OpenAI and Claude Code effectively blocked the actor's attempts to use those models, leading to the selection of DeepSeek due to its lack of guardrails. The incident highlights the operational value of AI safety controls in preventing misuse.

Key Points: • The campaign involved over 460 attempted attacks using DeepSeek AI and Hermes Agent. • Only three successful compromises were confirmed, primarily involving data exfiltration from Citrix NetScaler. • OpenAI's safety controls effectively blocked the threat actor's attempts to use their models for offensive tasks.

ThreatCluster AI How this analysis works

Timeline

2025-12-19
CVE-2025-68613 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-07
CVE-2026-21858 published
CVE-2026-21858 was published with a first public proof-of-concept released on 2023-10-12.
Techtimes
2026-03-20
CVE-2026-33017 published
CVE-2026-33017, a critical vulnerability, was published and later added to CISA KEV for active exploitation.
Techtimes
2026-03-30
CVE-2026-3055 added to CISA KEV
CVE-2026-3055 was added to CISA KEV for active exploitation, highlighting its critical nature.
Oodaloop
2026-04-09
CVE-2026-39987 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-01
Unit 42 publishes findings on the campaign
Palo Alto Networks' Unit 42 published a report detailing the autonomous cyberattack campaign and its implications.
Techtimes
Recent
Campaign exposed via accidental HTTP server launch
The Hermes Agent accidentally launched a public HTTP server, leaking API keys and logs, revealing the campaign's details.
Forkast.News

Community

Browse all →