CYBERSECURITYTRACKER
TRACKING6,626 stories in this site build1,366 vulnerability news stories in this site build
Permanent story citation

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3620

As cited

Copy frozen at (site build).

ai security

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks' Unit 42 discovered a Chinese-speaking threat actor using DeepSeek, an AI model, through the open-source Hermes Agent framework to conduct autonomous attacks. The attacker issued instructions via Telegram, and the agent independently identified internet-facing systems and deployed public exploits without further operator involvement. The operator uses the aliases knaithe and KnYuan.

Why it matters: Security teams need to understand that AI models can be weaponized for fully autonomous attack chains with minimal human direction, expanding the threat surface for organizations with exposed systems and unpatched vulnerabilities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks' Unit 42 documented a Chinese-speaking threat actor using the DeepSeek language model with the open-source Hermes Agent framework to execute autonomous cyberattacks. Following a single Telegram command, the agent independently identified internet-facing systems and deployed public exploits with no further operator intervention required. The actor operates under the aliases knaithe and KnYuan.

Why it matters: Security teams need to monitor for autonomous attack agents leveraging large language models, as they reduce operator overhead and may enable faster, less detectable intrusions against exposed systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks' Unit 42 documented a Chinese-speaking threat actor using the DeepSeek language model with the open-source Hermes Agent framework to execute autonomous cyberattacks. Following a single Telegram command, the agent independently identified internet-facing systems and deployed public exploits with no further operator intervention required. The actor operates under the aliases knaithe and KnYuan.

Why it matters: Security teams need to monitor for autonomous attack agents leveraging large language models, as they reduce operator overhead and may enable faster, less detectable intrusions against exposed systems.

VendorsPalo Alto Networks
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary