n8n: China-based hacker employs DeepSeek in autonomous threat campaign

n8n: China-based hacker employs DeepSeek in autonomous threat campaign

Chinese-Speaking Threat Actor Leverages DeepSeek AI in Autonomous Hacking Campaign

A Chinese-speaking threat actor recently conducted an AI-driven hacking campaign using DeepSeek, China’s AI platform, alongside the Hermes Agent framework to automate vulnerability discovery. According to a Unit 42 report by Palo Alto Networks, the attacker scanned GitHub for trending proof-of-concept (POC) exploits, targeting n8n, an open-source workflow automation tool.

The campaign involved a chained vulnerability in n8n, combining an arbitrary file read flaw and a remote-code execution (RCE) flaw. However, the attack failed because the exploit required either auto-login to be enabled or a public flow ID, neither of which were present in the targeted systems.

Researchers noted the actor also experimented with Western AI tools, including Claude Code and Codex, for connectivity testing and proxy validation. While the intent behind targeting these tools remains unclear whether strategic or opportunistic Unit 42’s Andy Piazza suggested the selection may have been arbitrary.

The campaign highlights the growing use of AI-powered autonomous hacking, though in this case, the actor eventually resorted to manual operations for successful exploitation. Notably, the threat actor was not linked to any state-backed group, operating independently.

The incident underscores the evolving tactics of cybercriminals, particularly in sectors like manufacturing, where IT/OT convergence has increased vulnerability exposure. While this attack was unsuccessful, it reflects broader trends in AI-driven cyber threats and the expanding toolkit available to malicious actors.

Source: https://www.cybersecuritydive.com/news/china-based-hacker-deepseek-autonomous/826784/

n8n cybersecurity rating report: https://www.rankiteo.com/company/n8n

"id": "N8N1785774219",
"linkid": "n8n",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology/Software',
                        'name': 'n8n',
                        'type': 'Open-source workflow automation tool'}],
 'attack_vector': 'AI-driven vulnerability scanning, GitHub POC exploits',
 'description': 'A Chinese-speaking threat actor conducted an AI-driven '
                'hacking campaign using DeepSeek, China’s AI platform, '
                'alongside the Hermes Agent framework to automate '
                'vulnerability discovery. The attacker scanned GitHub for '
                'trending proof-of-concept (POC) exploits, targeting n8n, an '
                'open-source workflow automation tool. The campaign involved a '
                'chained vulnerability in n8n, combining an arbitrary file '
                'read flaw and a remote-code execution (RCE) flaw, but failed '
                'due to missing prerequisites. The actor also experimented '
                'with Western AI tools like Claude Code and Codex. The '
                'incident highlights the growing use of AI-powered autonomous '
                'hacking, though the actor resorted to manual operations for '
                'successful exploitation.',
 'lessons_learned': 'The incident underscores the evolving tactics of '
                    'cybercriminals, particularly the growing use of '
                    'AI-powered autonomous hacking and the expanding toolkit '
                    'available to malicious actors. It also highlights the '
                    'risks in sectors like manufacturing where IT/OT '
                    'convergence increases vulnerability exposure.',
 'post_incident_analysis': {'root_causes': 'AI-driven vulnerability scanning, '
                                           'exploitation of chained '
                                           'vulnerabilities in n8n, and '
                                           'experimentation with Western AI '
                                           'tools for connectivity testing and '
                                           'proxy validation.'},
 'references': [{'source': 'Unit 42 (Palo Alto Networks)'}],
 'threat_actor': 'Chinese-speaking threat actor (independent, not '
                 'state-backed)',
 'title': 'Chinese-Speaking Threat Actor Leverages DeepSeek AI in Autonomous '
          'Hacking Campaign',
 'type': 'Autonomous Hacking Campaign',
 'vulnerability_exploited': ['Arbitrary file read flaw',
                             'Remote-code execution (RCE) flaw']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.