Unit 42 documented an autonomous AI-enabled cyberattack campaign in which a Chinese-speaking threat actor used DeepSeek (via the Hermes Agent framework) as an autonomous offensive operator, orchestrated through Telegram, to independently perform reconnaissance via FOFA, source public exploit PoCs from GitHub, and attempt exploitation across seven CVEs affecting Langflow, n8n, Citrix NetScaler, Apache Tomcat, Marimo Notebook, PAN-OS, and Windows IKE VPN extensions. The actor also evaluated Western AI tools (Claude Code, Codex) in a limited testing capacity routed through an anti-attribution proxy, but relied on DeepSeek due to its lack of provider-side safety restrictions; while most autonomous exploitation attempts failed due to target-side configuration barriers, manual campaigns achieved confirmed data exfiltration from Citrix NetScaler targets, and the AI agent's own actions inadvertently exposed the entire operational infrastructure.
Hermes Agent
1 post
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks