Chinese Threat Actor Uses DeepSeek and Hermes Agent to Launch Fully Autonomous Cyberattacks
ID: 103c05b7-195c-5cb5-8d4d-4e0a76be3b87
STIX ID: report--103c05b7-195c-5cb5-8d4d-4e0a76be3b87
Feed Name: CosmicBytez Labs
Unit 42 documents a landmark autonomous offensive AI campaign in which a Chinese-speaking operator instructed a Hermes Agent once via Telegram and the agent (DeepSeek) autonomously scanned 460+ targets, chained exploits across seven vulnerability families (including CVE-2026-21858 CVSS 10.0 and CVE-2026-33017 CVSS 9.8), achieved 11 confirmed RCEs and three confirmed data exfiltrations, and left recoverable operational artifacts (IP 43.246.208.207, stolen credentials), demonstrating rapid, scalable attacks and recommending urgent patching, FOFA recon monitoring, and audit of AI agent deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
