AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek
ID: c3c89ee7-2aa9-515f-aa77-d26ff4efba94
STIX ID: report--c3c89ee7-2aa9-515f-aa77-d26ff4efba94
Feed Name: Security Affairs
Unit 42 documented a Chinese-speaking threat actor (knaithe / KnYuan) using an AI autonomous operator (DeepSeek) wired into the Hermes Agent framework to rapidly enumerate, assess, and attempt exploitation of internet-exposed services; exposed operation artifacts revealed API keys, exploit scripts and session logs. DeepSeek autonomously scanned large populations (e.g., ~647k n8n instances), chained vulnerabilities, and although many autonomous attempts failed due to target configuration, Unit 42 confirmed successful data exfiltration from three Citrix NetScaler instances and command execution on 11 Marimo notebook endpoints, demonstrating a significant escalation in attack scale and speed when AI is used for autonomous offensive operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
