A Chinese hacker exploits DeepSeek for autonomous attacks against vulnerable servers
A Chinese threat group, identified by the aliases "knaithe" and "KnYuan", has used advanced language models to automate cyberattacks against internet-exposed systems, minimizing human intervention. The discovery is the work of researchers from Palo Alto Networks' Unit 42, who identified the criminal infrastructure thanks to a file server misconfiguration.
Quick Response
- The group exploited DeepSeek as a reasoning agent for autonomous attacks
- The infrastructure was discovered due to a misconfigured server
- Vulnerabilities such as CVE-2026-33017 and CVE-2026-21858 were identified
- Manual attacks succeeded by exploiting CVE-2026-3055 in Citrix NetScaler
The criminal infrastructure and the misconfiguration
The misconfiguration allowed Unit 42 experts to analyze the entire criminal infrastructure, understanding both the arsenal used and the attack methodology. The aggressors orchestrated a campaign that exploited various artificial intelligence platforms to conduct autonomous attacks.
DeepSeek and the autonomy of attacks
The analysis of session logs and configuration files revealed that the attackers primarily used the Hermes agent with DeepSeek as a reasoning agent for the attack phase of the campaign. The Hermes agent autonomously conducted vulnerability enumeration, downloaded public exploit code from the internet, and attempted to exploit the targets.
The autonomous attack chain
After receiving instructions via Telegram, the agent worked autonomously, searching for internet-exposed systems through the FOFA search engine, downloading exploit code from GitHub, and launching attacks without further operator input. In addition to DeepSeek, the group used other language models such as Qwen, GLM, Kimi, and MiniMax, with limited use of Western tools like Claude Code and Codex.
The analysis of vulnerabilities and target selection
In a recovered session, the AI agent targeted a vulnerability in Langflow, tracked as CVE-2026-33017 with a severity score of 9.8. The agent downloaded a public exploit from GitHub, identified 84 exposed Langflow servers through FOFA, and assessed their vulnerability. However, the attack failed because the required configuration was not enabled.
The analysis of vulnerabilities and target selection
The AI agent then analyzed public exploit repositories, evaluating the severity of vulnerabilities against the distribution scale before selecting n8n, a workflow automation platform identified by FOFA on over 647,000 internet-exposed servers worldwide, including more than 25,000 in China.
The exploit chain and the efficiency of the AI agent
The agent selected an exploit that chained two vulnerabilities: CVE-2026-21858, an arbitrary file read defect with a CVSS score of 10.0, and CVE-2025-68613, a sandbox escape vulnerability leading to remote code execution with a CVSS score of 9.9. Despite both vulnerabilities being patched in the latest versions of n8n, the AI agent determined that version 1.117.3 was vulnerable to the exploit chain.
The efficiency of the AI agent
The autonomous process of identification, sampling, and target restriction is noteworthy because the system executed hundreds of hours of manual targeting analysis in just a few minutes, also managing its own computing resources. Despite none of the autonomous attacks succeeding in compromising the systems, Unit 42 described the workflow as "a functional, end-to-end autonomous offensive capability".
Manual attacks and success against Citrix NetScaler
In addition to the AI-guided sessions, the threat group conducted manual attacks against more than 460 systems, targeting known vulnerabilities in Citrix NetScaler, Apache Tomcat, Marimo Notebook, and Windows IKE VPN, among others. Three of the manual attacks succeeded, all exploiting CVE-2026-3055 in Citrix NetScaler appliances. The attackers extracted data directly from the device's memory and searched for authentication cookies that could be used to hijack active user sessions.
Implications for cybersecurity
The discovery of this autonomous AI-driven campaign raises significant concerns for cybersecurity. The ability of attackers to automate complex attacks lowers the technical barrier for offensive operations, making it harder for organizations to defend against these threats. This underscores the urgent need for advanced security solutions that can detect and mitigate autonomous attacks effectively.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.