Chinese Threat Actor Leverages AI to Target Exposed Infrastructure in Asia
A Chinese-speaking threat actor, operating under the aliases knaithe and KnYuan and based in Zhuhai, China, has exploited large language models (LLMs) from both Chinese and Western providers to compromise internet-exposed digital infrastructure across Asia. According to a July 30 report by Unit 42, Palo Alto Networks’ threat intelligence team, the attacker used DeepSeek’s AI model and the Hermes Agent an open-source agentic AI framework to orchestrate the campaign via Telegram, significantly accelerating the speed and scale of their operations.
The actor, described as an opportunistic exploit operator and self-proclaimed binary security researcher, combined AI-driven enumeration with automated and manual exploitation of seven vulnerabilities. Their GitHub activity, including the maintenance of 1DayNews an automated vulnerability intelligence pipeline revealed a methodical approach to identifying and weaponizing flaws.
When initial exploitation attempts failed due to restrictive target configurations, the Hermes Agent, integrated with DeepSeek’s AI, autonomously searched for critical-severity CVEs across 10 product families. The AI scanned GitHub for trending proof-of-concept (PoC) exploits, prioritizing vulnerabilities based on attack surface before pivoting to seven higher-value flaws for targeted exploitation. This hybrid approach blending AI automation with manual refinement demonstrates an evolving threat landscape where adversaries increasingly rely on AI-augmented offensive tools to enhance efficiency and evade detection.
Source: https://www.infosecurity-magazine.com/news/chinese-hacker-deepseek-ai/
DeepSeek TPRM report: https://www.rankiteo.com/company/deepseek-ai
Hermes Agent TPRM report: https://www.rankiteo.com/company/nousresearch
"id": "deenou1785515277",
"linkid": "deepseek-ai, nousresearch",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': 'Asia'}],
'attack_vector': ['AI-driven enumeration',
'Automated exploitation',
'Manual exploitation',
'Telegram'],
'date_publicly_disclosed': '2024-07-30',
'description': 'A Chinese-speaking threat actor, operating under the aliases '
'*knaithe* and *KnYuan* and based in Zhuhai, China, has '
'exploited large language models (LLMs) from both Chinese and '
'Western providers to compromise internet-exposed digital '
'infrastructure across Asia. The attacker used DeepSeek’s AI '
'model and the Hermes Agent, an open-source agentic AI '
'framework, to orchestrate the campaign via Telegram, '
'significantly accelerating the speed and scale of their '
'operations. The actor combined AI-driven enumeration with '
'automated and manual exploitation of seven vulnerabilities. '
'The AI autonomously searched for critical-severity CVEs '
'across 10 product families and scanned GitHub for trending '
'proof-of-concept (PoC) exploits, prioritizing vulnerabilities '
'based on attack surface before pivoting to seven higher-value '
'flaws for targeted exploitation.',
'impact': {'systems_affected': 'Internet-exposed digital infrastructure '
'across Asia'},
'motivation': ['Opportunistic exploitation', 'Binary security research'],
'post_incident_analysis': {'root_causes': 'AI-augmented offensive tools, '
'exploitation of critical-severity '
'CVEs'},
'references': [{'date_accessed': '2024-07-30',
'source': 'Unit 42, Palo Alto Networks'}],
'threat_actor': {'aliases': ['knaithe', 'KnYuan'],
'location': 'Zhuhai, China',
'motivation': 'Opportunistic exploitation, binary security '
'research',
'name': ['knaithe', 'KnYuan']},
'title': 'Chinese Threat Actor Leverages AI to Target Exposed Infrastructure '
'in Asia',
'type': 'Cyber Attack',
'vulnerability_exploited': ['Seven critical-severity CVEs across 10 product '
'families']}