logo

Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm

ID: 0d5cf0fb-78c5-5532-9075-a41d983a4f02

STIX ID: report--0d5cf0fb-78c5-5532-9075-a41d983a4f02

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: Elizabeth Montalbano

...
...

Jesta Security discovered and intercepted an intentional, autonomous AI-driven proxyjacking campaign (attributed to a likely Chinese threat actor) that conducted rapid, repeated SSH reconnaissance and deployed MicroSocks SOCKS5 proxies on compromised servers to build relay infrastructure for future operations; Jesta engaged the agent to extract attribution and intelligence rather than simply blocking it, and recommends hardening credentials, exposed ports, and using deception (honeytokens/tripwires) to detect AI agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.