DeepSeek and Hermes Agent: Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits

DeepSeek and Hermes Agent: Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits

Chinese Threat Actor Leverages AI to Target Exposed Infrastructure in Asia

A Chinese-speaking threat actor, operating under the aliases knaithe and KnYuan and based in Zhuhai, China, has exploited large language models (LLMs) from both Chinese and Western providers to compromise internet-exposed digital infrastructure across Asia. According to a July 30 report by Unit 42, Palo Alto Networks’ threat intelligence team, the attacker used DeepSeek’s AI model and the Hermes Agent an open-source agentic AI framework to orchestrate the campaign via Telegram, significantly accelerating the speed and scale of their operations.

The actor, described as an opportunistic exploit operator and self-proclaimed binary security researcher, combined AI-driven enumeration with automated and manual exploitation of seven vulnerabilities. Their GitHub activity, including the maintenance of 1DayNews an automated vulnerability intelligence pipeline revealed a methodical approach to identifying and weaponizing flaws.

When initial exploitation attempts failed due to restrictive target configurations, the Hermes Agent, integrated with DeepSeek’s AI, autonomously searched for critical-severity CVEs across 10 product families. The AI scanned GitHub for trending proof-of-concept (PoC) exploits, prioritizing vulnerabilities based on attack surface before pivoting to seven higher-value flaws for targeted exploitation. This hybrid approach blending AI automation with manual refinement demonstrates an evolving threat landscape where adversaries increasingly rely on AI-augmented offensive tools to enhance efficiency and evade detection.

Source: https://www.infosecurity-magazine.com/news/chinese-hacker-deepseek-ai/

DeepSeek TPRM report: https://www.rankiteo.com/company/deepseek-ai

Hermes Agent TPRM report: https://www.rankiteo.com/company/nousresearch

"id": "deenou1785515277",
"linkid": "deepseek-ai, nousresearch",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': 'Asia'}],
 'attack_vector': ['AI-driven enumeration',
                   'Automated exploitation',
                   'Manual exploitation',
                   'Telegram'],
 'date_publicly_disclosed': '2024-07-30',
 'description': 'A Chinese-speaking threat actor, operating under the aliases '
                '*knaithe* and *KnYuan* and based in Zhuhai, China, has '
                'exploited large language models (LLMs) from both Chinese and '
                'Western providers to compromise internet-exposed digital '
                'infrastructure across Asia. The attacker used DeepSeek’s AI '
                'model and the Hermes Agent, an open-source agentic AI '
                'framework, to orchestrate the campaign via Telegram, '
                'significantly accelerating the speed and scale of their '
                'operations. The actor combined AI-driven enumeration with '
                'automated and manual exploitation of seven vulnerabilities. '
                'The AI autonomously searched for critical-severity CVEs '
                'across 10 product families and scanned GitHub for trending '
                'proof-of-concept (PoC) exploits, prioritizing vulnerabilities '
                'based on attack surface before pivoting to seven higher-value '
                'flaws for targeted exploitation.',
 'impact': {'systems_affected': 'Internet-exposed digital infrastructure '
                                'across Asia'},
 'motivation': ['Opportunistic exploitation', 'Binary security research'],
 'post_incident_analysis': {'root_causes': 'AI-augmented offensive tools, '
                                           'exploitation of critical-severity '
                                           'CVEs'},
 'references': [{'date_accessed': '2024-07-30',
                 'source': 'Unit 42, Palo Alto Networks'}],
 'threat_actor': {'aliases': ['knaithe', 'KnYuan'],
                  'location': 'Zhuhai, China',
                  'motivation': 'Opportunistic exploitation, binary security '
                                'research',
                  'name': ['knaithe', 'KnYuan']},
 'title': 'Chinese Threat Actor Leverages AI to Target Exposed Infrastructure '
          'in Asia',
 'type': 'Cyber Attack',
 'vulnerability_exploited': ['Seven critical-severity CVEs across 10 product '
                             'families']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.