Unit 42 Traces DeepSeek Agent in Mixed Attack Campaign
Palo Alto Networks' Unit 42 reported on July 30 that a Chinese-speaking operator used DeepSeek through Hermes Agent to automate reconnaissance and failed Langflow and n8n exploitation attempts within a broader campaign against more than 460 targets. Unit 42 attributed three confirmed compromises to separate manual NetScaler exploitation, while its report contains an unresolved inconsistency involving claimed Marimo command execution.
Palo Alto Networks' Unit 42 reported on July 30 that a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to automate parts of an offensive campaign. The operator, tracked under the aliases knaithe and KnYuan, used a mix of autonomous and manual techniques against more than 460 targets, according to the report.
The distinction matters: Unit 42 said the recovered autonomous DeepSeek sessions attempted exploitation but did not fully compromise their intended Langflow or n8n targets. The confirmed compromises described later in the report came from separate manual activity.
One instruction led to autonomous target selection
Unit 42 recovered a May 2026 Hermes Agent session controlled through Telegram. After the initial task, researchers found no further operator input in that session. The agent enumerated exposed systems, assessed vulnerable versions, downloaded public exploit code, and changed direction after target-side configuration requirements blocked its first attempt.
The agent then surveyed 10 product families and selected an n8n exploit chain for further testing. It found systems running vulnerable versions, but the required unauthenticated form configuration was absent, so the autonomous n8n attempts also failed.
Unit 42 describes seven exploit tracks in its table. The n8n track combines two CVE identifiers, meaning the table covers eight CVE identifiers even though the report refers to seven vulnerabilities.
Confirmed impact came from manual operations
Unit 42 separately reported conventional manual exploitation, including data exfiltration through a NetScaler memory-read vulnerability and command execution on Marimo notebook instances. Later, the same report says researchers could confirm only three successfully exploited targets across the entire operation and attributes those three to the NetScaler activity.
The Hacker News highlighted that the report does not reconcile its statement about command execution on 11 Marimo instances with the later total of three confirmed compromises. The available evidence therefore supports reporting the inconsistency, not choosing one success count as definitive.
The autonomous Langflow and n8n sequences nevertheless show a functioning reconnaissance and exploit-selection loop. The agent adapted after failures, sourced tools, and moved between targets without additional operator input recovered in the session.
The operational lesson is speed, not proven autonomy at scale
For defenders, the strongest takeaway is that an agent can compress reconnaissance, vulnerability prioritization, and exploit retrieval even when exploitation fails. Monitoring exposed services, rapid scanning, repository downloads, messaging-based control, and outbound exploit traffic can provide a broader view than model prompts alone.
Unit 42 identified the operator as Chinese-speaking and linked the aliases to public activity in Zhuhai. The report does not attribute the campaign to a nation-state group.
Key Points
- 1Unit 42 recovered a DeepSeek and Hermes Agent session that autonomously enumerated targets, selected exploits, and changed course after failed attempts.
- 2The autonomous Langflow and n8n attempts did not achieve compromise; Unit 42 tied three confirmed compromises to separate manual NetScaler exploitation.
- 3Unit 42's Marimo command-execution claim does not reconcile with its later three-target success total, so the article reports the inconsistency rather than resolving it.
Scoring Rationale
The report documents a concrete autonomous reconnaissance and exploit-selection loop, but the observed autonomous attempts failed and the confirmed compromises were attributed to manual activity. Its success-count inconsistency is material, so the practitioner value lies in the demonstrated workflow and defensive telemetry implications rather than an overstated compromise total.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

