A Chinese-speaking threat actor has been observed leveraging the DeepSeek tool via the Hermes Agent framework to conduct autonomous attacks, with initial instructions issued through Telegram. This approach enables the actor to identify and exploit internet-facing systems without requiring further manual input. The threat actor, known by aliases including knaithe and KnYuan, utilizes public exploits to carry out the attacks. The use of DeepSeek and Hermes Agent allows for a high degree of automation, making it a concerning development in the cyber threat landscape. Researchers at Palo Alto Networks' Unit 42 have been tracking this activity, shedding light on the tactics and techniques employed by the actor1. This matters to security practitioners because it highlights the growing trend of autonomous attacks, which can rapidly escalate and cause significant damage without timely intervention.
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
⚡ High Priority
Why This Matters
Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.
References
- Palo Alto Networks. (2026, July 31). Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks. *The Hacker News*. https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html
Original Source
The Hacker News
Read original →