knaithe, also known as KnYuan, is a China-based, Chinese-speaking threat actor assessed as an opportunistic exploit operator and self-described binary security researcher. The actor is notable for combining manual intrusion activity with AI-enabled autonomous offensive workflows, using DeepSeek as a reasoning engine through the Hermes Agent framework to automate vulnerability research, target selection, exploit retrieval, scanning, and exploitation attempts against exposed internet-facing systems. Observed autonomous operations used Hermes Agent with custom offensive-security skills and FOFA integration to enumerate exposed assets, identify candidate vulnerabilities, obtain public proof-of-concept exploit code, and attempt exploitation with limited human intervention. Documented autonomous targeting included Langflow and n8n, where the agent evaluated exploitability, scanned large target sets, and attempted exploitation but failed because target-side conditions such as authentication requirements or missing exposed identifiers prevented compromise. The activity nevertheless demonstrated an end-to-end autonomous attack workflow capable of compressing reconnaissance, exploit selection, and attack execution into a short time window. Separate manual operations were more successful. knaithe conducted attacks against hundreds of systems spanning Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products. Confirmed successful compromises involved exploitation of Citrix NetScaler systems via CVE-2026-3055, followed by memory extraction and searches for authentication cookies, indicating intent to hijack authenticated sessions. Additional manual activity included exploitation attempts against Marimo Notebook, Apache Tomcat, and Windows IKE VPN targets, though confirmed impact was limited compared with the broader volume of attempted targeting. The actor’s tradecraft includes reconnaissance, scanning, initial access via exploitation of public-facing applications, exfiltration of memory-resident data, and session hijacking-oriented post-exploitation. The operation also showed defense-evasion and anti-attribution awareness, including proxy use and configuration choices intended to reduce traceability when testing some AI platforms. The actor has also maintained tooling and workflows for automated vulnerability intelligence collection and triage, consistent with a rapid exploit-operator model focused on newly disclosed remote-code-execution opportunities. No high-confidence evidence supports ransomware or destructive operations. The dominant pattern is financially motivated opportunistic exploitation, with emphasis on harvesting access and valuable session material from vulnerable edge infrastructure. A persistently targeted Malaysian government entity was specifically noted among observed victims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A China-based threat actor used DeepSeek and Hermes Agent to conduct largely autonomous offensive operations against exposed servers, including vulnerability research, target discovery, exploit selection, scanning, and attempted exploitation. The actor also manually attacked hundreds of systems and successfully compromised some Citrix NetScaler targets.
Chinese-speaking opportunistic exploit operator using AI-enabled autonomous and manual exploitation workflows. Used Hermes Agent with DeepSeek for autonomous target enumeration, exploit sourcing, vulnerability research, and attack attempts, while also conducting manual exploitation with confirmed data exfiltration and command execution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.