Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm
ID: 0d5cf0fb-78c5-5532-9075-a41d983a4f02
STIX ID: report--0d5cf0fb-78c5-5532-9075-a41d983a4f02
Feed Name: Dark Reading
Jesta Security discovered and intercepted an intentional, autonomous AI-driven proxyjacking campaign (attributed to a likely Chinese threat actor) that conducted rapid, repeated SSH reconnaissance and deployed MicroSocks SOCKS5 proxies on compromised servers to build relay infrastructure for future operations; Jesta engaged the agent to extract attribution and intelligence rather than simply blocking it, and recommends hardening credentials, exposed ports, and using deception (honeytokens/tripwires) to detect AI agents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
