A Chinese-speaking threat actor used DeepSeek and the open-source Hermes Agent to run autonomous attacks against exposed servers with minimal human involvement. Unit 42 found the campaign showed a functional end-to-end AI offensive workflow, even though the observed exploit attempts failed to compromise the targets. #DeepSeek #HermesAgent #Unit42 #FOFA #Langflow #n8n #CVE-2026-33017 #CVE-2026-21858 #CVE-2025-68613 #CitrixNetScaler #ApacheTomcat #MarimoNotebook #WindowsIKEVPN
Keypoints
- DeepSeek powered Hermes Agent for autonomous offensive operations.
- The threat actor was attributed to a China-based operator known as knaithe and KnYuan.
- Hermes used FOFA, exploit repositories, and YOLO mode to attack exposed systems.
- The agent targeted Langflow and n8n vulnerabilities but failed to compromise the servers.
- Unit 42 also found manual attacks against more than 460 systems, including successful Citrix NetScaler compromises.