A Chinese threat actor has strategically exploited large language models (LLMs) offered by both Chinese and Western technology companies to compromise digital infrastructure exposed to the internet in Asia. This sophisticated actor has notably utilized a specific AI framework called Hermes Agent from DeepSeek, which is an open-source agentic AI system, to manage and orchestrate fundamentally disruptive activities, primarily through the messaging platform Telegram.
Andy Piazza, a senior director of threat intelligence at Palo Alto Networks’ Unit 42, highlighted that these AI-driven offensive capabilities have significantly enhanced the speed and scale of the attacking campaigns. This insight came as part of a detailed report published on July 30, which unveiled the operational strategies being employed by cybercriminals in today’s technologically advanced landscape.
AI Orchestration and Manual Exploitation Tactics
The cybercriminal in question, reportedly a Chinese-speaking individual operating under the aliases ‘knaithe’ and ‘KnYuan,’ is believed to be based in Zhuhai, China. Piazza characterized the individual as “an opportunistic exploit operator and self-described binary security researcher,” based on their activity on GitHub. This includes maintaining a project named 1DayNews, which serves as an automated vulnerability intelligence pipeline designed to identify and exploit weaknesses in digital infrastructure.
In conducting their attacks, the threat actor targeted infrastructure that was specifically exposed to the internet. They ingeniously combined automated, AI-driven processes for identifying and exploiting vulnerabilities with both automated and manual exploitation techniques concerning seven specific vulnerabilities. When initial attempts at exploitation were thwarted due to the restrictive configurations of the target environments, the Hermes Agent—powered by a DeepSeek AI model—took over. This AI system autonomously conducted thorough searches for known critical-severity Common Vulnerabilities and Exposures (CVEs).
Initially, the agent focused on surveying ten product families while scanning repositories on GitHub for trending proofs of concept (PoC) exploits, subsequently prioritizing vulnerabilities based on the attack surface they presented. This meticulous research led the Hermes Agent to pivot toward seven higher-value vulnerabilities, including:
- CVE-2026-33017 (CVSS rating: 9.8): A vulnerability in Langflow, where autonomous exploitation attempts were unsuccessful due to disabled auto-login features.
- CVE-2026-21858 (CVSS rating: 10.0): An n8n Workflow Automation vulnerability that failed in autonomous exploitation due to the necessity for authentication.
- CVE-2025-68613 (CVSS rating: 9.9): Another n8n Workflow Automation vulnerability, similarly thwarted in autonomous exploitation attempts due to authentication requirements.
- CVE-2026-3055 (CVSS rating: 9.8): A vulnerability in Citrix NetScaler ADC & Gateway that was manually exploited, leading to data exfiltration.
- CVE-2026-34486 (CVSS rating: 7.5): Involving Apache Tomcat, manual exploitation attempts focused on establishing reverse shells.
- CVE-2026-39987 (CVSS rating: 9.8): A vulnerability in Marimo Notebook that led to confirmed command execution through manual exploitation.
- CVE-2026-0300 (CVSS rating: 9.8): Pertaining to PAN-OS User-ID Authentication Portal, where manual non-functional research on a PoC was cloned but not executed.
- CVE-2026-33824 (CVSS rating: 9.8): A Windows IKE Extensions (IKE VPN) vulnerability, where manual exploitation led to attempts at establishing reverse shells.
Trial and Exploration of AI Tools
Alongside their use of DeepSeek as an autonomous operational platform, the actor configured a range of LLMs. These included various Chinese models (Qwen, GLM, Kimi, MiniMax) as well as limited testing and utilization of Western AI tools like Claude Code for connectivity testing and proxy validation. Furthermore, OpenAI’s Codex was harnessed in directories focused on exploit development. Piazza suggested that this limited experimentation and evaluation of various AI tools indicated the actor’s attempt to ascertain the most effective tools for their operations.
While the observed campaign did not achieve a full compromise of any of the designated targets, the methodology underscores a functioning, end-to-end autonomous offensive capability. The targets for these operations spanned multiple sectors and included nations such as China and Malaysia.
Piazza concluded with an emphasis on the evolving nature of these cyber threats, asserting that the key takeaway from this campaign lies more in its trajectory than its outcomes. The actor is continually refining their tool configurations, developing unique skills, establishing proxy infrastructures, and executing increasingly sophisticated autonomous attack cycles. The technical barriers to engaging in AI-enhanced offensive operations are diminishing, presenting a growing concern for cybersecurity professionals tasked with defending against such advanced tactics.

