Chinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm
ID: 033c4508-2663-5211-9105-566ead91033b
STIX ID: report--033c4508-2663-5211-9105-566ead91033b
Feed Name: CosmicBytez Labs
**Executive summary:** Unit 42 documented the first confirmed autonomous AI-driven attack campaign (attributed to an opportunistic Chinese-speaking operator "knaithe") that wired an open-source LLM (DeepSeek) into the Hermes Agent framework and used Telegram for C2 to autonomously discover, select, and attempt exploitation of vulnerable internet-facing services; the campaign attempted exploitation of hundreds to thousands of hosts, leveraged at least eight CVEs across seven tracks (several actively exploited and on CISA KEV), and produced confirmed compromises (including Citrix NetScaler and Marimo notebook instances), demonstrating that agentic AI attacks are now occurring in the wild and amplifying low-sophistication actors' reach.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
