knaithe, also known as KnYuan, is a Chinese-speaking threat actor assessed to be based in Zhuhai, China. The actor has been characterized as an opportunistic exploit operator and self-described binary security researcher. The activity attributed to this actor is notable for combining conventional intrusion tradecraft with an AI-enabled autonomous offensive workflow built around the Hermes Agent framework and DeepSeek, with additional testing of other large language models including Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI Codex. The actor targeted internet-facing infrastructure in Asia and was observed attacking organizations in China and Malaysia. Confirmed victimology includes a Malaysian government entity, and the broader activity spanned multiple sectors, including government and public sector targets. The actor’s operations focused on exposed enterprise and server software, including Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE Extensions, Langflow, and n8n. A distinguishing feature of this actor is operational use of autonomous AI for parts of the intrusion lifecycle. In observed sessions, Hermes Agent received high-level tasking and then autonomously performed reconnaissance, internet asset discovery through FOFA, vulnerability research, exploit acquisition from public repositories, target prioritization, and attempted exploitation. The autonomous workflow was seen evaluating multiple product families, abandoning low-probability paths, and pivoting toward vulnerabilities with larger exposed attack surfaces and high severity. Although the observed autonomous exploitation attempts against Langflow and n8n did not achieve confirmed compromise, the activity demonstrated a functional end-to-end offensive workflow with limited human intervention. Alongside the AI-enabled activity, knaithe conducted manual exploitation against hundreds of targets. Confirmed successful operations involved exploitation of Citrix NetScaler vulnerabilities to extract memory contents and search for authentication material, indicating both data theft and session hijacking objectives. Additional manual activity included command execution against Marimo Notebook instances and reverse-shell attempts against Apache Tomcat and Windows IKE-related targets. The actor also cloned and evaluated public proof-of-concept exploit code for additional products, reflecting opportunistic exploitation of newly disclosed vulnerabilities. The actor’s tradecraft includes reconnaissance, scanning, exploitation of public-facing applications, exploit development or adaptation from public proof-of-concept code, exfiltration, and session hijacking-oriented post-exploitation. The campaign also showed use of proxy infrastructure and other anti-attribution measures when interacting with AI tooling. Overall, knaithe represents an early example of a China-based threat actor operationalizing agentic AI to accelerate vulnerability research, target selection, and attack execution while retaining manual intervention for higher-value or more complex exploitation steps.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Separately, the Chinese-speaking adversary has been found conducting manual operations using known vulnerabilities in Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and IKE VPN (CVE-2026-33824) endpoints.
Separately, the Chinese-speaking adversary has been found conducting manual operations using known vulnerabilities in Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and IKE VPN (CVE-2026-33824) endpoints.
Separately, the Chinese-speaking adversary has been found conducting manual operations using known vulnerabilities in Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and IKE VPN (CVE-2026-33824) endpoints.
CVE-2026-34486 (CVS score: 7.5) - A missing encryption of sensitive data vulnerability in Apache Tomcat that allows a bypass of EncryptInterceptor, a cluster component that adds pre-shared key encryption to messages sent between cluster nodes. (Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117)
When initial attempts to exploit a Langflow flaw (CVE-2026-33017, CVSS 9.8) breach failed due to the target environment's restrictive configurations, the AI agent is said to have conducted autonomous research to identify other higher-value vulnerabilities, including flaws in n8n, to find a way in.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting an AI-enabled autonomous and manual exploitation campaign against internet-exposed devices, including use of DeepSeek via the Hermes Agent framework and exploitation of multiple known vulnerabilities.
Chinese-speaking threat actor conducting autonomous and manual internet-facing server attacks using DeepSeek and the Hermes Agent framework, including vulnerability discovery, exploit retrieval, target enumeration, and exploitation attempts against Langflow, n8n, Citrix NetScaler, Marimo Notebook, and Windows IKE VPN.
Used multiple LLMs and an AI agent (Hermes Agent with DeepSeek) to automate vulnerability enumeration, exploit selection, public exploit retrieval, and attacks against internet-facing systems; also conducted manual exploitation, including successful attacks against Citrix NetScaler appliances.
Conducting an AI-assisted offensive campaign using autonomous tooling for vulnerability discovery, public PoC acquisition, internet-wide scanning, attempted exploitation of public-facing applications, and confirmed manual exploitation leading to data exfiltration and command execution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.