Quick Answer
A standalone attack exposed by a misconfiguration
A Chinese-speaking threat actor used the DeepSeek AI model and the open-source Hermes agent to conduct standalone attacks against exposed servers. The campaign, discovered by researchers at Palo Alto Networks' Unit 42, was made visible by a misconfiguration in the Hermes agent that created a web server from its home directory, exposing the entire attacker environment.
The exposed infrastructure reveals compromising details
The exposure allowed researchers to access API keys, exploit scripts, target lists, shell history, and AI attack logs. Unit 42 attributed the activity to a China-based actor operating under the aliases "knaithe" and "KnYuan," self-identifying as a "binary security researcher."
DeepSeek and Hermes: a framework for standalone attacks
The DeepSeek model was used as the reasoning engine behind Hermes Agent, an open-source framework capable of interacting with operating system terminals, executing commands, and connecting to the Internet. Hermes supports a "YOLO" mode that allows the agent to execute commands, even risky ones, without first requesting permission from the operator.
The standalone attack step by step
Unit 42 recovered a session from May 2026 in which the operator provided only an initial task, after which the agent conducted the remaining activity autonomously. The agent first targeted Internet-exposed Langflow servers vulnerable to CVE-2026-33017, downloading a public proof-of-concept, identifying 84 exposed instances via the FOFA search engine, and scanning them for vulnerable configurations.
The autonomous search for vulnerabilities
After determining that the available targets could not be exploited, the agent sought other potential vulnerabilities. DeepSeek analyzed multiple public exploit repositories before selecting the n8n workflow automation platform as a target, with over 647,000 exposed instances identified via FOFA. The agent downloaded an exploit that chained CVE-2026-21858 and CVE-2025-68613, identifying servers running vulnerable versions and checking them for unauthenticated file upload modules required to complete the attack.
The significance of the autonomous campaign
Unit 42 emphasizes that the campaign is significant because the agent independently conducted vulnerability research, determined which targets were the best options, downloaded exploit code, and then attempted to exploit the targets found. This process, which would normally require many hours, was executed in a few minutes by the autonomous agent.
Parallel manual attacks
While the AI agent was used extensively, the threat actor also conducted manual attacks against more than 460 systems, exploiting vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products. Unit 42 confirmed three successful compromises that exploited the Citrix NetScaler vulnerability CVE-2026-3055, used to extract memory and search for authentication cookies that could be used for session hijacking.
Other AI coding platforms configured but little used
The actor had configured other AI coding platforms, including Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI's Codex. However, Unit 42 found that these tools were not frequently used during the campaign.
Hermes used in previous attacks
This incident adds to another recent one, in which poorly protected Hermes infrastructure exposed details about an alleged cyberattack against Thailand's Ministry of Finance. Hunt.io and researcher Bob Diachenko discovered open web directories containing exploit tools, web shells, credentials, compiled payloads, and Hermes activity logs.
Post-exploitation automation
The logs showed Hermes running in unsupervised "YOLO" mode to automate post-exploitation activity, including searching for privilege escalation opportunities, service enumeration, container inspection, filesystem traversal, and cataloging archived documents on the Ministry of Finance systems. However, this previous incident did not show Hermes autonomously choosing the target or determining how to compromise it.
The implications for cybersecurity
These campaigns highlight the evolution of standalone attacks and the importance of adopting proactive cybersecurity measures. This includes not only strengthening perimeter defenses but also implementing advanced attack detection and response solutions. Techniques such as breach and attack simulation, for example, can help test the effectiveness of existing security systems and identify potential gaps before they can be exploited.
The future of standalone attacks
As technology continues to evolve, it is likely that standalone attacks will become increasingly common and sophisticated. This raises important ethical and security questions, including the need for regulation and standardization of cybersecurity practices. Additionally, the cybersecurity community will need to collaborate to develop new techniques and tools capable of effectively countering these emerging threats.
Lessons learned
The standalone attack campaign described by Unit 42 offers valuable lessons for the cybersecurity community. First, it highlights the need for greater vigilance and constant monitoring of IT infrastructures. Second, it underscores the importance of keeping systems up to date and applying security patches promptly to prevent the use of known vulnerabilities. Finally, it demonstrates that automation can be a double-edged sword, with potential applications both offensive and defensive.
The need for global collaboration
Addressing the threat of standalone attacks requires a coordinated global response. This includes sharing information among organizations, collaboration between governments and the private sector, and the development of common standards for cybersecurity. Only through a collaborative approach will it be possible to develop effective solutions and protect critical infrastructures from these emerging threats.
The emergence of standalone attacks represents a significant challenge for cybersecurity, but also an opportunity to innovate and improve existing defenses. As technology continues to evolve, it is essential that organizations adopt a proactive and collaborative approach to address these threats. Only through collective effort will it be possible to ensure the security of digital infrastructures in an increasingly interconnected and interdependent world.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: the reader is invited to always inform themselves independently before making any decision.