CVE Tools

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Palo Alto Unit 42By Andy Piazza14 min read

PoC publicHermes AgentknaitheFOFA

Our summary

A Chinese-speaking threat actor has deployed AI models to conduct autonomous cyberattacks, leveraging tools like DeepSeek and Hermes Agent to identify and exploit vulnerabilities in infrastructure. The actor, known as knaithe or KnYuan, used FOFA for asset discovery and targeted seven critical vulnerabilities, including CVE-2026-33017 and CVE-2026-21858. While some attacks failed due to target-side configurations, the campaign demonstrates a functional end-to-end autonomous offensive capability. Palo Alto Networks offers protections through Cortex XDR, XSIAM, and Next-Generation Firewall.

Read at Palo Alto Unit 42

Below is the opening; the full story is at Palo Alto Unit 42.

From Palo Alto Unit 42

Executive Summary

Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact.

The actor, operating under the aliases knaithe and KnYuan, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator. They orchestrated this operator via Telegram for the following activities:…

Continue at Palo Alto Unit 42

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store