Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
PoC publicHermes AgentknaitheFOFAOur summary
A Chinese-speaking threat actor has deployed AI models to conduct autonomous cyberattacks, leveraging tools like DeepSeek and Hermes Agent to identify and exploit vulnerabilities in infrastructure. The actor, known as knaithe or KnYuan, used FOFA for asset discovery and targeted seven critical vulnerabilities, including CVE-2026-33017 and CVE-2026-21858. While some attacks failed due to target-side configurations, the campaign demonstrates a functional end-to-end autonomous offensive capability. Palo Alto Networks offers protections through Cortex XDR, XSIAM, and Next-Generation Firewall.
Below is the opening; the full story is at Palo Alto Unit 42.
From Palo Alto Unit 42
Executive Summary
Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact.
The actor, operating under the aliases knaithe and KnYuan, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator. They orchestrated this operator via Telegram for the following activities:…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.