Researchers Discover DeepSeek-Powered Autonomous Cyberattack Campaign
Key Takeaways
- ▸Threat actors are leveraging DeepSeek AI and open-source frameworks like Hermes Agent to automate cyberattack workflows, reducing manual effort from hours to minutes
- ▸The autonomous AI system independently researched vulnerabilities, identified 647,000+ exposed n8n instances, downloaded exploits, and executed attacks without human feedback between actions
- ▸Unit 42 researchers discovered the campaign after Hermes Agent accidentally exposed the attacker's environment, including API keys, exploit scripts, target lists, and AI attack logs
Summary
Palo Alto Networks' Unit 42 researchers have discovered a Chinese-speaking threat actor using the DeepSeek AI model and the open-source Hermes Agent framework to conduct autonomous cyberattacks against vulnerable servers with minimal human intervention. The threat actor configured the system to accept instructions via Telegram and employ offensive security skills, allowing the AI agent to independently research vulnerabilities, identify potential targets through the FOFA internet asset search engine, download exploit code, and attempt attacks—automating processes that typically require hours of manual work. While the autonomous attacks on Langflow and n8n platforms failed to successfully compromise targets, the campaign demonstrates a functional end-to-end offensive AI workflow capable of discovering, evaluating, and executing attacks autonomously. The same threat actor also conducted manual attacks using traditional exploit methods, successfully compromising at least three systems using the Citrix NetScaler vulnerability CVE-2026-3055.
- The observed autonomous attacks ultimately failed, but the campaign demonstrates practical offensive AI capabilities that could be refined for future, more sophisticated threats
- Multiple AI models are being configured for offensive security purposes, including Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI's Codex, though DeepSeek was the primary model observed
Editorial Opinion
This research marks a critical inflection point: AI's rapid adoption in security tools now creates dual-use risks that threat actors are actively exploiting. While the observed attacks ultimately failed, the campaign's methodical automation of reconnaissance and exploitation represents a significant escalation in adversarial AI capabilities. The security community must accelerate development of defenses specifically designed for AI-powered attacks, and AI companies need stronger safeguards against their models being repurposed for offensive operations.



