A Chinese-speaking threat actor successfully used large language models from both Chinese and Western companies to attack internet-exposed digital infrastructure across Asia, leveraging DeepSeek's Hermes Agent to orchestrate the campaign through Telegram. The report from Unit 42, the research arm of Palo Alto Networks, was released on July 30 and documents what researchers describe as a functional, end-to-end autonomous offensive capability. The actor combined AI-driven enumeration with both automated and manual exploitation of seven separate vulnerabilities to target systems in three countries, including China and Malaysia.
The individual operates under the aliases 'knaithe' and 'KnYuan' and is based in Zhuhai, China, according to the report. When initial automated exploitation failed because of restrictive target configurations, the actor's Hermes Agent—connected to a DeepSeek AI model—autonomously searched for known critical-severity vulnerabilities. The agent surveyed 10 product families, scanned GitHub for trending proof-of-concept exploits, and ranked vulnerabilities by attack surface before pivoting to seven higher-value targets. These included CVE-2026-33017, a Langflow vulnerability rated 9.8 on the CVSS scale where autonomous exploitation failed, and CVE-2026-21858, an n8n Workflow Automation flaw rated 10.0 where authentication blocked the attack. Manual exploitation succeeded on CVE-2026-3055, a Citrix NetScaler vulnerability rated 9.8 that resulted in data exfiltration, and CVE-2026-39987, a Marimo Notebook flaw rated 9.8 where command execution was confirmed. The actor also attempted reverse shell access through CVE-2026-34486, an Apache Tomcat vulnerability rated 7.5, and CVE-2026-33824, a Windows IKE VPN flaw rated 9.8.
Andy Piazza, senior director of threat intelligence at Unit 42, said the AI-augmented offensive capabilities "enabled them to dramatically increase the speed and scale of their campaigns." The report notes the actor configured multiple Chinese language models, including Qwen, GLM, Kimi, and MiniMax, alongside limited testing of Western tools such as Claude Code for connectivity testing and OpenAI's Codex on exploit development directories. Piazza described this limited Western AI usage as "consistent with evaluating the AI-market to identify their preferred tool set." While the campaign achieved limited impact and didn't fully compromise any intended targets, the workflow confirms a working autonomous offensive capability, according to the report. The actor maintains 1DayNews, an automated vulnerability intelligence pipeline on GitHub, which researchers used to identify them as an opportunistic exploit operator and self-described binary security researcher.
The report emphasizes that the campaign's significance lies in its direction rather than its immediate results. Piazza noted the actor is actively refining tool configurations, developing custom skills, establishing proxy infrastructure, and executing autonomous attack cycles. The technical barrier to AI-augmented offensive operations is low and continues to drop, the researcher added. The observation window captured activity on May 5, 2026, showing an autonomous attack flow within the Hermes Agent session that moved from initial reconnaissance to vulnerability prioritization to exploitation attempts without human intervention. The workflow demonstrates how commercially available AI tools can be repurposed to automate tasks that previously required significant manual effort, compressing timelines and lowering the skill threshold for conducting multi-stage cyberattacks across borders.

