Unit 42 Documents DeepSeek Autonomous Attack Campaign
Palo Alto Networks Unit 42 reported on July 30 that a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to autonomously enumerate targets, source exploit tools, and initiate attacks. Unit 42 attributed the activity to an operator using the aliases knaithe and KnYuan, and reported confirmed but limited impact across attacks involving seven vulnerabilities.
Palo Alto Networks' Unit 42 reported on July 30 that a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework as an autonomous offensive operator. Unit 42 tracked the operator under the aliases knaithe and KnYuan, and reported that the campaign combined AI-driven reconnaissance with manual exploitation against infrastructure using seven vulnerabilities.
According to Unit 42, the operator controlled the agent through Telegram. After receiving an initial instruction, the agent independently enumerated targets and vulnerabilities, sourced exploit tools, and initiated attacks without further human intervention observed in that session. IT Security News, republishing a report attributed to The Hacker News, similarly reported that researchers recovered no additional operator input after the initial Telegram command.
Autonomous reconnaissance and exploit selection
Unit 42 reported that initial exploitation attempts failed because of restrictive configurations in the target environment. The Hermes Agent then searched for known critical-severity CVEs, surveyed 10 product families, reviewed trending proof-of-concept exploits on GitHub, and prioritized vulnerabilities by attack surface.
The research team wrote that this process led the agent to select seven higher-value vulnerabilities. Unit 42 characterized the observed impact as limited, while concluding that the workflow demonstrated a functioning end-to-end autonomous offensive capability.
The actor also configured multiple LLMs, including GLM, Kimi, and MiniMax, alongside DeepSeek, Unit 42 reported. The researchers found limited testing of Western platforms for connectivity and proxy validation, as well as indications of use on exploit-development directories. Unit 42 described that activity as consistent with evaluating available AI tools.
What the campaign demonstrates
The report is notable because it describes an agentic workflow rather than a model merely generating code or answering attacker prompts. In comparable security incidents, chaining reconnaissance, vulnerability prioritization, tool retrieval, and attack execution can reduce the human effort required to operate at scale. That makes telemetry across messaging controls, agent hosts, code repositories, scanning activity, and outbound exploit traffic more important than monitoring model prompts alone.
Unit 42's account also underscores a practical boundary: the agent encountered target-side restrictions, then changed its research and vulnerability-selection path. For defenders, comparable agent-driven campaigns can compress the interval between internet exposure discovery and exploitation attempts, particularly where public proof-of-concept code is readily available.
It identifies the actor as Chinese-speaking and uses the two aliases, rather than attributing the campaign to a nation-state group.
Key Points
- 1Unit 42 documented an agentic attack workflow that connected reconnaissance, exploit discovery, and attack initiation through DeepSeek and Hermes Agent.
- 2The campaign reportedly involved seven vulnerabilities and limited confirmed impact, but demonstrated autonomous task switching after failed exploitation attempts.
- 3Comparable agent-driven attacks can shorten reconnaissance-to-exploitation cycles, increasing the value of correlating exposure, scanning, repository, and network telemetry.
Scoring Rationale
The report provides a concrete, recently documented example of an LLM agent being used across multiple offensive security stages. It is especially relevant to practitioners building or securing agentic systems, though Unit 42 described the campaign's confirmed impact as limited.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems


