Palo Alto Networks' Unit 42 discovered a Chinese-speaking threat actor using DeepSeek, an open-source AI model, to execute autonomous cyberattacks with minimal human intervention. The operator, identified by the aliases knaithe and KnYuan, issued a single command via Telegram that triggered the Hermes Agent framework to launch attacks independently.
The attack sequence demonstrates a troubling shift in threat actor methodology. After receiving the initial instruction, the AI agent identified internet-facing systems, selected publicly available exploits, and executed attacks without requiring additional operator guidance. Researchers found no evidence of follow-up commands during the observed session, indicating the framework operated autonomously once activated.
The Hermes Agent framework, an open-source tool, acts as a wrapper around AI models to enable autonomous task execution. In this case, it transformed DeepSeek from a conversational tool into an attack orchestration platform. The operator leveraged Telegram as a command channel, a common tactic among threat actors seeking operational security and deniability.
This incident reflects an emerging threat landscape where adversaries combine large language models with open-source automation frameworks to scale attack capabilities. DeepSeek, which gained prominence as a cost-effective alternative to Western AI models, became a weapon platform in this scenario. The model's ability to reason about network topology, identify vulnerable systems, and select appropriate exploits created a force multiplier for the attacker.
The implications for defending organizations are substantial. Traditional detection relies on identifying operator behavior patterns and command sequences. Autonomous agents eliminate this fingerprint. Security teams must now contend with attacks launched without human interaction, compressed timelines, and adversaries who delegate tactical decisions to AI systems.
Unit 42's recovery of the attack session provided a rare window into this capability. The threat actor demonstrated both technical sophistication and operational security discipline. Organizations should immediately review logs for suspicious Deep
