CyberSecurity SEE

Chinese Hacker Leverages DeepSeek and Hermes Agent for Autonomous Cyberattacks

Chinese Hacker Leverages DeepSeek and Hermes Agent for Autonomous Cyberattacks

Cybersecurity Threat Actor Utilizes AI Tools for Sophisticated Attacks

A recent investigation has revealed that a Chinese-speaking threat actor is employing advanced automated tools, notably DeepSeek in conjunction with the Hermes Agent framework, to conduct comprehensive reconnaissance, vulnerability research, exploitation acquisition, and numerous attack attempts against internet-facing infrastructure. This intelligence comes from Unit 42, a cybersecurity research team known for monitoring emerging digital threats.

Emergence of AI-Driven Offensive Operations

Operating under the aliases "knaithe" and "KnYuan," this particular threat actor has constructed an AI-enhanced offensive environment. This setup merges DeepSeek’s reasoning capabilities with Hermes Agent’s terminal access features and Telegram-based command-and-control functionality. The integration also utilizes reusable attack “skills” designed for automation, showcasing a frightening trend where attackers increasingly rely on artificial intelligence to streamline their malicious operations and reduce human involvement.

This campaign serves as a stark demonstration of the potential for agentic AI systems to navigate through much of the attack lifecycle with minimal human oversight. Given the growing sophistication of such tools, the cybersecurity community is now faced with unprecedented challenges in defending against AI-fueled cyber threats.

Unintended Discovery of Operations

Remarkably, researchers gained insight into the operation when an unintentional event occurred: the Hermes Agent activated a Python HTTP file server from the attacker’s home directory. This misstep exposed crucial information about the actor’s configuration and tools. The disclosures included configurations of various hacking tools, API keys, target lists, scripts for exploitation, and logs detailing autonomous attack sessions.

DeepSeek functioned as the core reasoning engine, while the Hermes Agent oversaw the execution of vulnerabilities. The actor cleverly devised custom skills for a range of tasks, including Large Language Model (LLM) jailbreaking, exploiting unauthenticated WebSocket connections, and utilizing FOFA for asset discovery.

Autonomous Reconnaissance and Targeting

One intriguing aspect of the operations was the integration of a Multi-Channel Protocol (MCP) server, which facilitated the translation of natural language prompts into FOFA queries. This attribute allowed for automated generation of Nuclei scans and expansive searches for assets across the internet.

In one of several operational sessions that were later recovered, the actor independently accessed a public proof-of-concept exploit addressing the Langflow vulnerability identified by the CVE-2026-33017 designation, which carries a critical Common Vulnerability Scoring System (CVSS) rating of 9.8. This particular effort exposed 84 vulnerable Langflow instances through FOFA queries, ultimately leading to the identification of a single vulnerable host running version 1.3.4 of Langflow.

However, despite these attempts, the exploitation was unsuccessful. The target default settings, which included the absence of the necessary auto_login setting and an undisclosed public flow ID, thwarted further exploitation efforts. Instead of persisting in ineffective attempts, the AI agent displayed adaptive behavior by evaluating the Langflow target as low priority and pivoting toward threats perceived as more impactful.

Shifting Focus to Higher-Value Targets

The DeepSeek-powered agent went on to examine ten different product families, scouring resources like GitHub to identify trending vulnerabilities for 2026. Its evaluation process resulted in a prioritization of n8n workflow automation, which unveiled over 647,000 exposed instances globally, including a significant count from within China itself.

The campaign’s focus turned to two vulnerabilities, CVE-2026-21858 and CVE-2025-68613, both critical flaws that open doors to arbitrary file-reading and remote code execution potential, respectively. Once again, the autonomous system undertook the task of downloading public exploits, sourced out seemingly vulnerable n8n versions, and hunted for form-upload endpoints essential for executing the planned exploitation.

Challenges with Secure Configurations

Despite the extensive operational execution, all identified upload forms required authentication, preventing any successful breaches. In lieu of further progress, the agent continued its pursuit, scanning over 50 more targets primarily located within China, yet still failed to locate publicly accessible upload forms.

While it is crucial to note that these AI-directed campaigns did not culminate in verified compromises, Unit 42 documented successful manual intrusions by the same threat actor. Notably, the attacker managed to extract sensitive data from three different organizations by exploiting vulnerabilities associated with Citrix NetScaler and managed to execute commands on numerous Marimo notebook instances.

Other disturbing activities comprised attempts at establishing reverse shells against both Apache Tomcat servers and Windows IKE VPN endpoints, indicating a wide-ranging focus on infiltrating over 460 systems via both automated and manual operations.

A Concerning Trend in Cyber Threats

The detected activity concerning Citrix NetScaler is particularly alarming, as it revealed the actor actively searching through stolen memory data for ‘NSC_AAAC’ authentication cookies. This suggests a calculated effort to hijack active sessions, raising significant concerns regarding the security of sensitive information within compromised systems.

Evidence also emerged of targeted campaigns against a Malaysian government entity, propelled by a refined approach to exploitation and the utilization of proxy anonymizations. Such a shift represents a marked transition from mere AI-assisted scripting towards more semi-autonomous offensive operations capable of carrying out invasive tactics with minimal human intervention.

Conclusion

To combat these evolving threats, cybersecurity defenders are urged to prioritize rapid patching of internet-facing platforms, minimize reliance on unauthenticated administrative and file-upload interfaces, and maintain a constant inventory of exposed assets. Furthermore, organizations are advised to actively monitor for reconnaissance activities indicative of FOFA-style searches, unusual bulk version checks, and any attempt at public proof-of-concept exploitation targeting workflow automations, VPNs, and edge devices.

While this particular actor’s autonomy faced challenges due to stringent security configurations, the research underscores a significant shift in the capabilities of AI agents, allowing them to discover, assess and pivot between targets at an unprecedented machine speed.

Source link

Exit mobile version