Knaithe is an apt_group tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
Knaithe is a apt_group tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed July 30, 2026; most recent activity July 30, 2026.
A Chinese-speaking threat actor, identified as knaithe/KnYuan, executed an autonomous cyberattack campaign using DeepSeek AI and the Hermes Agent framework. The campaign targeted over 460 servers, attempting to exploit…
Knaithe is an apt_group tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
The most recent intelligence report mentioning Knaithe on ThreatCluster is dated July 30, 2026.
Across ThreatCluster reporting, Knaithe most frequently co-occurs with KnYuan, MiniMax, T1071 - Application Layer Protocol, Qwen, Telegram, among 11 tracked related entities.
The most significant recent cluster is “DeepSeek AI Used in Autonomous Cyberattack Campaign by Chinese Threat Actor” (5 articles · Updated August 2, 2026). Knaithe appears across 1 threat cluster in total, listed above with sources.
Knaithe appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.