← Back to blog

Chinese Hacker Uses AI Agent for Autonomous Cyberattacks

A Chinese-speaking attacker leveraged the DeepSeek AI model via Telegram to conduct autonomous cyber operations. The AI agent scanned for vulnerabilities and executed public exploits without further human input.

TL;DR

  • Chinese threat actor used DeepSeek AI through Hermes Agent framework
  • Attacks were initiated via Telegram with no further operator involvement
  • AI agent autonomously identified targets and applied known exploits
  • Incident highlights growing use of AI in offensive cyber operations
  • Organizations should monitor for unusual scanning and exploit activity

Security researchers at Palo Alto Networks' Unit 42 have uncovered a sophisticated attack campaign where a Chinese-speaking threat actor utilized an AI agent to conduct autonomous cyberattacks. The attacker employed the DeepSeek large language model through the open-source Hermes Agent framework, issuing initial commands via Telegram before the AI system took over the operation.

This represents a significant evolution in automated attack methodologies, where artificial intelligence is being weaponized to reduce human involvement in cyber operations. The incident demonstrates how readily available AI tools can be repurposed for malicious activities, potentially scaling the reach and frequency of cyber threats.

Attack Methodology

  • Operator used aliases knaithe and KnYuan to deploy the Hermes Agent framework
  • Initial command was sent through Telegram messaging platform
  • DeepSeek AI model was configured to operate autonomously after receiving instructions
  • No further human input was detected during the attack session
  • Agent independently scanned for internet-facing systems and vulnerabilities

Autonomous Operations

  • AI agent automatically selected and deployed public exploits against discovered targets
  • System demonstrated ability to conduct reconnaissance without operator guidance
  • Attack chain completed without additional Telegram communications from operator
  • Researchers observed full compromise cycle executed by autonomous agent
  • Incident shows potential for AI to accelerate attack timelines significantly

Defensive Implications

  • Organizations need enhanced monitoring for automated scanning patterns
  • Traditional incident response may require adaptation for AI-driven attacks
  • Security teams should prepare for reduced human-operated attack windows
  • Increased emphasis needed on vulnerability management and patch deployment
  • Detection strategies must evolve to identify autonomous threat behaviors

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.