Palo Alto Networks Unit 42 reported that a Chinese-speaking threat actor used an AI-enabled offensive workflow built around Hermes Agent and the DeepSeek model to autonomously scan the internet, identify vulnerable systems, evaluate exploit paths, and launch attacks against exposed services. The activity initially targeted Langflow instances and later shifted to n8n servers after unsuccessful exploitation attempts, showing a repeatable machine-driven cycle of reconnaissance, exploit research, and attack execution with limited human intervention.
Researchers said the campaign did not achieve full compromise through the autonomous workflow alone, but the same actor also conducted manual intrusions that successfully exploited Citrix NetScaler devices, obtained command execution on Marimo notebook instances, and attempted reverse-shell access against Apache Tomcat and VPN targets. Unit 42 gained rare visibility into the operation after Hermes accidentally exposed the operator’s home directory through a public HTTP file server, revealing scripts, target lists, API settings, shell history, and autonomous session logs that showed AI-assisted cyberattacks are already operationally viable against internet-facing infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Unit 42 attributed the Hermes Agent and DeepSeek-enabled activity to a Chinese-speaking threat actor using the aliases knaithe and KnYuan, reportedly based in Zhuhai, China. The report also linked the actor to Telegram-based orchestration and custom offensive Hermes modules.
Jesta Security reported that an autonomous DeepSeek v4 'Flash free' agent began attacking its network on July 2, using hundreds of short-lived SSH sessions over five days to conduct reconnaissance and attempt deployment of MicroSocks SOCKS5 proxies. Jesta said it uncovered a target list of 1,283 hosts with credentials and assessed that about 1,000 additional internet-exposed victims, mostly SMBs, were also targeted to build relay infrastructure for follow-on attacks.
Separate manual operations attributed to the same actor successfully exploited Citrix NetScaler devices, achieved command execution on Marimo notebook instances, and attempted reverse-shell access against Apache Tomcat and VPN targets. These actions were described as distinct from the autonomous Hermes-led exploitation attempts.
Researchers gained visibility into the campaign after Hermes mistakenly exposed the operator’s home directory through an internet-accessible HTTP file server. The exposed data included scripts, target lists, API configurations, command history, and autonomous session logs.
Unit 42 reported that a Chinese-speaking threat actor used an offensive workflow built around Hermes Agent and the DeepSeek model to autonomously scan for vulnerable internet-facing systems, assess exploit paths, and launch attacks with limited human intervention. The activity initially targeted exposed Langflow instances and later shifted to n8n after failed exploitation attempts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcedarkreading.com
Open sourcesecurityaffairs.com
Open sourcehelpnetsecurity.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceunit42.paloaltonetworks.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.