Chinese Threat Actor Leverages AI for Autonomous Cyberattacks
Researchers at Palo Alto Networks’ Unit 42 have uncovered a campaign by a China-based threat actor using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks with minimal human oversight. The actor, operating under the aliases "knaithe" and "KnYuan," identifies as a "binary security researcher."
The discovery stemmed from an accidental exposure of the attacker’s environment after Hermes created a misconfigured web server, revealing API keys, exploit scripts, target lists, shell history, and AI attack logs. While the observed attacks did not successfully compromise targets, they demonstrated a fully autonomous offensive AI workflow capable of identifying, evaluating, and exploiting vulnerabilities.
AI-Powered Attack Workflow
The threat actor deployed DeepSeek as the reasoning engine behind Hermes Agent, an AI framework that interacts with operating systems, executes commands, and connects to the internet. Hermes was configured to:
- Receive instructions via Telegram
- Use custom offensive-security tools
- Query FOFA, an internet asset search engine
- Operate in "Yolo" mode, executing commands without prior approval
In a recovered session from May 2026, the agent autonomously:
- Targeted Langflow servers vulnerable to CVE-2026-33017, scanning 84 exposed instances but failing to exploit them.
- Switched to n8n workflow automation, identifying 647,000 exposed instances and attempting to exploit CVE-2026-21858 and CVE-2025-68613 though authentication requirements prevented successful breaches.
- Analyzed public exploit repositories and executed hundreds of hours of manual targeting analysis in minutes, managing its own compute resources.
Manual Attacks & Successful Compromises
While the AI-driven attacks were largely unsuccessful, the threat actor also conducted manual attacks on 460+ systems, exploiting vulnerabilities in:
- Citrix NetScaler (CVE-2026-3055) – Used in three confirmed breaches to extract memory and harvest authentication cookies.
- Apache Tomcat, Marimo Notebook, Windows IKE VPN, and others.
Additional AI platforms (Qwen, GLM, Kimi, MiniMax, Claude Code, OpenAI Codex) were configured but rarely used.
Previous Hermes Incident in Thailand
This campaign follows a separate incident where poorly secured Hermes infrastructure exposed details of an alleged cyberattack on Thailand’s Ministry of Finance. Logs revealed Hermes operating in unattended "YOLO" mode, automating post-exploitation tasks such as:
- Privilege escalation checks
- Service enumeration
- File system traversal
- Document cataloging
Unlike the autonomous attacks observed by Unit 42, the Thailand incident involved human-directed targeting, with Hermes only automating post-compromise activity.
Significance of the Campaign
Unit 42 highlights the evolution of AI-driven cyber threats, where autonomous agents can:
- Research vulnerabilities independently
- Prioritize targets
- Download and execute exploits
- Adapt attack strategies in real time
While this campaign had limited success, it underscores the growing sophistication of offensive AI in cyber operations.
Microsoft Threat Intelligence cybersecurity rating report: https://www.rankiteo.com/company/microsoft-threat-intelligence
The Apache Software Foundation cybersecurity rating report: https://www.rankiteo.com/company/the-apache-software-foundation
SecureLayer7 cybersecurity rating report: https://www.rankiteo.com/company/securelayer7
Citrix cybersecurity rating report: https://www.rankiteo.com/company/citrix
"id": "MICTHESECCIT1785522270",
"linkid": "microsoft-threat-intelligence, the-apache-software-foundation, securelayer7, citrix",
"type": "Vulnerability",
"date": "5/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Public Sector',
'location': 'Thailand',
'name': 'Thailand’s Ministry of Finance',
'type': 'Government'},
{'industry': ['Technology', 'Finance', 'Government'],
'location': 'Global',
'type': 'Various organizations'}],
'attack_vector': ['Autonomous AI agent (Hermes Agent)',
'Exploiting known vulnerabilities (e.g., CVE-2026-33017, '
'CVE-2026-21858, CVE-2025-68613, CVE-2026-3055)'],
'data_breach': {'sensitivity_of_data': 'High (authentication credentials)',
'type_of_data_compromised': ['Authentication cookies']},
'date_detected': '2026-05',
'description': 'Researchers at Palo Alto Networks’ Unit 42 uncovered a '
'campaign by a China-based threat actor using the DeepSeek AI '
'model and the open-source Hermes Agent to conduct autonomous '
'cyberattacks with minimal human oversight. The actor, '
"operating under the aliases 'knaithe' and 'KnYuan,' "
'demonstrated a fully autonomous offensive AI workflow capable '
'of identifying, evaluating, and exploiting vulnerabilities. '
'While the observed attacks did not successfully compromise '
'targets, the threat actor also conducted manual attacks on '
'460+ systems, exploiting vulnerabilities in Citrix NetScaler, '
'Apache Tomcat, Marimo Notebook, and Windows IKE VPN.',
'impact': {'data_compromised': ['Authentication cookies (Citrix NetScaler '
'breaches)'],
'systems_affected': '460+ systems (including Citrix NetScaler, '
'Apache Tomcat, Marimo Notebook, Windows IKE '
'VPN)'},
'investigation_status': 'Ongoing',
'lessons_learned': 'The campaign highlights the evolution of AI-driven cyber '
'threats, where autonomous agents can research '
'vulnerabilities, prioritize targets, download and execute '
'exploits, and adapt attack strategies in real time. While '
'this campaign had limited success, it underscores the '
'growing sophistication of offensive AI in cyber '
'operations.',
'post_incident_analysis': {'root_causes': ['Misconfigured web server exposing '
'API keys and attack logs',
'Use of autonomous AI agents for '
'vulnerability scanning and '
'exploitation',
'Manual exploitation of known '
'vulnerabilities']},
'references': [{'source': 'Palo Alto Networks’ Unit 42'}],
'response': {'third_party_assistance': 'Palo Alto Networks’ Unit 42'},
'threat_actor': 'China-based threat actor (aliases: knaithe, KnYuan)',
'title': 'Chinese Threat Actor Leverages AI for Autonomous Cyberattacks',
'type': ['AI-driven cyberattack', 'Manual exploitation'],
'vulnerability_exploited': ['CVE-2026-33017 (Langflow servers)',
'CVE-2026-21858 (n8n workflow automation)',
'CVE-2025-68613 (n8n workflow automation)',
'CVE-2026-3055 (Citrix NetScaler)',
'Apache Tomcat vulnerabilities',
'Marimo Notebook vulnerabilities',
'Windows IKE VPN vulnerabilities']}