{"id":68444,"date":"2026-08-22T14:24:13","date_gmt":"2026-08-22T14:24:13","guid":{"rendered":"https:\/\/www.europesays.com\/france\/68444\/"},"modified":"2026-08-22T14:24:13","modified_gmt":"2026-08-22T14:24:13","slug":"chinese-hacker-uses-deepseek-and-hermes-agent-to-launch-autonomous-cyberattacks","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/france\/68444\/","title":{"rendered":"Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks"},"content":{"rendered":"<p class=\"wp-block-paragraph\">A Chinese-speaking threat actor has been observed using DeepSeek through the Hermes Agent framework to automate reconnaissance, vulnerability research, exploit acquisition, and attack attempts against internet-facing infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">According to Unit 42, the actor tracked under the aliases knaithe and KnYuan built an AI-assisted offensive environment that combined DeepSeek\u2019s reasoning capabilities with Hermes Agent\u2019s terminal access, <a href=\"https:\/\/gbhackers.com\/millenium-rat-uses-base64-and-xor\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Telegram-based command-and-control<\/a> functionality, and reusable attack \u201cskills.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The campaign demonstrates how threat actors can use agentic AI systems to execute much of the attack lifecycle with limited human interaction.<\/p>\n<p class=\"wp-block-paragraph\">Researchers gained visibility into the operation after the Hermes Agent unintentionally launched a Python HTTP file server from the attacker\u2019s home directory. <\/p>\n<p>Chinese Hacker Uses DeepSeek and Hermes Agent <\/p>\n<p class=\"wp-block-paragraph\">The exposure reportedly revealed tool configurations, API keys, target lists, exploit scripts, shell history, and autonomous attack-session logs.<\/p>\n<p class=\"wp-block-paragraph\">DeepSeek acted as the primary reasoning engine, while Hermes Agent orchestrated execution. The actor configured custom skills for LLM jailbreaking, unauthenticated WebSocket exploitation, and FOFA-based asset discovery. <\/p>\n<p class=\"wp-block-paragraph\">They also integrated an MCP server capable of translating natural-language prompts into FOFA queries, generating Nuclei scans, and conducting internet-wide asset searches.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/france\/wp-content\/uploads\/2026\/08\/chinese-hacker-uses-deepseek-ai-to-automate-vulnerability-exploitation2-6a893f33e8c7d.webp\" alt=\"Attack flow (Source: Palo Alto Network)&#10;\"\/>Attack flow (Source: Palo Alto Network)<\/p>\n<p class=\"wp-block-paragraph\">In one recovered session from May 2026, the agent independently downloaded a public proof-of-concept exploit for Langflow vulnerability <a href=\"https:\/\/gbhackers.com\/langflow-cve-2026-33017-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-33017<\/a>, rated CVSS 9.8. It identified 84 exposed Langflow instances through FOFA, scanned them, and found one vulnerable host running Langflow 1.3.4.<\/p>\n<p class=\"wp-block-paragraph\">However, exploitation failed because the target lacked the required auto_login setting and did not expose a public flow ID. Rather than continuing unsuccessful attempts, the AI agent assessed Langflow as low value and pivoted autonomously toward higher-impact vulnerabilities.<\/p>\n<p class=\"wp-block-paragraph\">The DeepSeek-powered agent then surveyed 10 product families, searched GitHub for trending 2026 vulnerability PoCs, and ranked candidates by severity, exposure, and likelihood of exploitation. <\/p>\n<p class=\"wp-block-paragraph\">It selected n8n workflow automation as a priority target after identifying more than 647,000 exposed instances globally, including 25,209 in China.<\/p>\n<p class=\"wp-block-paragraph\">The attack chain targeted <a href=\"https:\/\/gbhackers.com\/over-100000-internet-exposed-n8n-instances\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-21858<\/a>, an arbitrary file-read flaw with a CVSS score of 10.0, and <a href=\"https:\/\/gbhackers.com\/n8n-vulnerability-allows-remote-attackers-to-hijack-systems\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2025-68613<\/a>, a sandbox-bypass vulnerability rated 9.9 that could lead to remote code execution.<\/p>\n<p class=\"wp-block-paragraph\">The autonomous system downloaded a public exploit, identified three apparently vulnerable n8n versions, and searched for exposed form-upload endpoints required for exploitation. <\/p>\n<p class=\"wp-block-paragraph\">All identified forms required authentication, preventing compromise. The agent subsequently scanned more than 50 additional Chinese targets but did not find publicly accessible upload forms.<\/p>\n<p class=\"wp-block-paragraph\">Although the AI-directed campaigns did not result in confirmed compromises, Unit 42 reported successful manual activity by the same actor. <\/p>\n<p class=\"wp-block-paragraph\">The threat actor allegedly exfiltrated data from three organizations by exploiting Citrix NetScaler vulnerability <a href=\"https:\/\/gbhackers.com\/hackers-probe-citrix-netscaler-systems-cve-2026-3055-exploitation\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-3055<\/a> and achieved command execution on 11 Marimo notebook instances via<a href=\"https:\/\/gbhackers.com\/weaponized-cve-2026-39987\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> CVE-2026-39987<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Other activities included attempts at reverse shells against Apache Tomcat servers and Windows IKE VPN endpoints. The actor reportedly targeted more than 460 systems across autonomous and manual campaigns.<\/p>\n<p class=\"wp-block-paragraph\">The Citrix NetScaler activity was especially concerning: the operator searched stolen memory data for NSC_AAAC authentication cookies, suggesting an effort to hijack active sessions. <\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/autonomous-ai-cyber-attack-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Palo Alto Networks also observed<\/a> repeated targeting of a Malaysian government entity using refined exploitation parameters and proxy anonymization.<\/p>\n<p class=\"wp-block-paragraph\">The campaign highlights a practical shift from AI-assisted scripting to semi-autonomous offensive operations. Defenders should prioritize rapid patching of internet-facing systems, minimize the use of unauthenticated administrative and file-upload interfaces, and continuously inventory exposed assets.<\/p>\n<p class=\"wp-block-paragraph\">Organizations should also monitor for FOFA-style reconnaissance, unusual bulk-version checks, public PoC scanning behavior, and exploitation attempts targeting workflow automation, VPN, and edge devices. <\/p>\n<p class=\"wp-block-paragraph\">While this actor\u2019s autonomous attacks were stopped by secure configuration requirements, the research shows that AI agents can now discover, assess, and pivot between targets at machine speed.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\">Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs:\u00a0<a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=csn&amp;utm_medium=100+links&amp;utm_campaign=lookup+tier+1&amp;utm_content=ti+lookup+sales&amp;utm_term=190826#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Integrate TI\u00a0Lookup in\u00a0your SOC<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"A Chinese-speaking threat actor has been observed using DeepSeek through the Hermes Agent framework to automate reconnaissance, vulnerability&hellip;\n","protected":false},"author":2,"featured_media":68445,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12919],"tags":[4997,36117,4953],"class_list":["post-68444","post","type-post","status-publish","format-standard","has-post-thumbnail","category-hermes","tag-cyber-security","tag-cyber-security-news","tag-hermes"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/posts\/68444","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/comments?post=68444"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/posts\/68444\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/media\/68445"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/media?parent=68444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/categories?post=68444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/tags?post=68444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}