Chinese-Speaking Hacker Used DeepSeek and Hermes Agent to Automate Attacks on More Than 460 Systems

Image: Chinaselectcommittee.house
Main Takeaway
A Chinese-speaking threat actor used DeepSeek through Hermes Agent to automate reconnaissance and exploitation across more than 460 internet-facing systems, researchers said.
Jump to Key PointsSummary
The campaign at a glance
A Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to automate reconnaissance and attempted exploitation against more than 460 internet-facing systems, according to Palo Alto Networks’ Unit 42. The campaign targeted organizations in Asia and combined automated scanning with human-directed exploitation, making it a practical demonstration of AI-assisted intrusion rather than a fully independent cyber operation.
The actor, identified by the aliases knaithe and KnYuan, controlled the agent through Telegram. Unit 42 said the operation tested 7 vulnerabilities and produced confirmed impact when manual intervention supplemented the automated workflow. Coverage from The Hacker News, Infosecurity Magazine and Cybersecurity Dive described the same campaign as an effort to scale offensive activity with relatively accessible AI tools.
How DeepSeek fit the workflow
DeepSeek served as the language-model component inside Hermes Agent, which acted as the operational layer for issuing instructions and coordinating tasks. A single Telegram command directed the system to identify exposed infrastructure, investigate targets and pursue weaknesses, according to Unit 42 and The Hacker News.
The arrangement shifted repetitive work from the operator to software. Automated enumeration can cover more systems in less time, while a human can select targets, adjust instructions and step in when exploitation requires judgment. Infosecurity Magazine quoted Andy Piazza of Unit 42 saying the combination increased the speed and scale of the campaign. The use of both Chinese and Western AI models also indicates that the actor treated model access as a practical resource rather than a matter of national provenance.
Automation had clear limits
The campaign remained a hybrid operation because the AI system did not complete every stage reliably. Cybersecurity Dive reported that the actor tested Western AI tools but returned to manual operations when automated attempts failed. Confirmed compromise therefore depended on human expertise alongside model-generated activity.
That distinction matters for defenders. AI reduced the cost of scanning, triage and task coordination, but it didn't remove the need for operators who understand vulnerabilities and infrastructure. The observed workflow also gives security teams a concrete detection target: unusual bursts of reconnaissance, command traffic routed through messaging platforms, and rapid attempts against several known weaknesses. Unit 42’s account links successful impact to the combination of autonomous enumeration and manual exploitation, rather than to DeepSeek operating alone.
A broader model supply chain
The incident places open-source agent frameworks alongside commercial and open-weight models in the offensive toolkit. Hermes Agent supplied the coordination layer, while DeepSeek handled language-model tasks; other reporting described experiments involving Western systems, including Claude Code in a separate suspected campaign involving government targets.
Hunt said an exposed directory tied to TencShell infrastructure contained evidence of activity affecting government systems in Afghanistan, Thailand and Taiwan, with probing involving financial targets. Reconshield described a split-model workflow using Claude Code and DeepSeek, but its account is less detailed and carries a lower reliability rating. Those reports concern related China-linked activity, not necessarily the same operation. Together, they show how attackers can assemble capabilities from multiple providers and frameworks, complicating attribution and policy controls.
Why defenders should care
The immediate security risk is scale. Internet-facing systems remain exposed to automated discovery, and an agent can keep scanning while an operator focuses on the few targets that warrant deeper attention. The campaign also demonstrates that sophisticated model training isn't required to produce operational value; a general-purpose model, an open-source framework and a messaging channel were enough to support a large targeting effort.
DeepSeek's role also intensifies scrutiny of AI governance and data handling. A 2025 report from the U.S. House Select Committee’s China committee accused DeepSeek of creating national-security and data risks, while the current incident shows how the model’s availability can intersect with offensive cyber operations. The findings don't establish that DeepSeek authorized or supported the attacks. They do show why model providers, framework maintainers and network defenders all face pressure to monitor abuse without assuming that model-level safeguards will stop every downstream use.
What happens next
Security teams should treat agent-enabled reconnaissance as an operational risk and tighten controls around exposed services, vulnerability remediation and outbound automation channels. Logging Telegram-linked infrastructure, rate-limiting scanning activity and reviewing unusual sequences of discovery followed by exploit attempts can help identify similar campaigns.
The episode also raises a policy challenge for AI companies. Blocking one model won't remove the workflow because operators can test several providers, run open models and switch to manual techniques when automation breaks down. Unit 42’s findings point to an evolving balance: agents can amplify attacker productivity, but reliable compromise still depends on infrastructure access, known vulnerabilities and human direction.
Key Points
DeepSeek powered Hermes Agent in an autonomous campaign targeting more than 460 internet-facing systems.
Unit 42 identified 7 vulnerabilities and confirmed impact after automated reconnaissance and manual exploitation.
Telegram let the Chinese-speaking operator issue instructions and coordinate the AI-assisted attack workflow.
Western AI tools were tested, but manual operations remained necessary when automated exploitation failed.
Open-source frameworks and general-purpose models are lowering the cost of large-scale cyber reconnaissance.
Questions Answered
The Chinese-speaking hacker used DeepSeek through Hermes Agent to automate reconnaissance and vulnerability-focused tasks. Telegram served as the control channel for issuing instructions, while human operators handled decisions and exploitation when automation failed.
The DeepSeek-assisted campaign targeted more than 460 internet-facing systems. Unit 42 said the operation examined 7 vulnerabilities and achieved confirmed impact through a mix of automated scanning and manual exploitation.
DeepSeek did not conduct the attacks entirely on its own. The campaign relied on Hermes Agent, Telegram coordination and human intervention, especially when automated exploitation was unsuccessful.
The DeepSeek campaign matters because it shows how accessible AI tools can increase the speed and scale of reconnaissance. Defenders must watch for high-volume scanning, rapid exploit attempts and command activity connected to messaging platforms.
Other AI models were involved in related reporting, including Western tools and Claude Code. Those accounts describe separate or related suspected activity and don't establish that every campaign belonged to the same operator.
Source Reliability
56% of sources are trusted · Avg reliability: 72
Go deeper with Organic Intel
Simple AI systems for your life, work, and business. Each one includes copyable prompts, guides, and downloadable resources.
Explore Systems