A Chinese-speaking operator used DeepSeek via the Hermes agent framework to autonomously attack 460+ targets
2026-deepseek-hermes-autonomous-campaign · 2026-07-30
Unit 42 documented a campaign in which a Chinese-speaking operator paired the open-source Hermes agent framework (terminal access, a skills system, and Telegram command-and-control) with DeepSeek as the reasoning engine to autonomously assess targets, generate commands, gather exploit tools, and choose where to focus — launching exploitation attempts against 460+ targets. It was uncovered when Hermes accidentally exposed the attacker's own environment.
System
- Framework
- Hermes agent framework with DeepSeek as reasoning engine
- Models
- deepseek
- Tools
- hermes, telegram, pentesting-utilities
- Vendor
- Chinese-speaking operator (aliases knaithe / KnYuan)
- Autonomy
- fully-autonomous
Classification
- Primary class
- autonomous-misuse
- Chain
- autonomous-misuse/cyber-ops
- Attack vector
- direct-user
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
The operator ran the Hermes agent framework with DeepSeek as its reasoning engine, controlling it over Telegram. In a recovered May 2026 session the operator provided only an initial task, after which the agent autonomously surveyed product families, searched GitHub for trending vulnerability proof-of-concepts, prioritised widely exposed software (identifying 647,000+ exposed n8n instances), and launched exploitation attempts across 460+ targets.
Root cause
An open-source agent framework plus a capable model turned a single operator's intent into an autonomous attack pipeline — assessing targets, generating commands, gathering tools, and adapting focus without continuous human input.
Contributing factors
- An open-source agent framework (Hermes) provided terminal access, a skills system, and Telegram C2.
- A capable reasoning model (DeepSeek) drove target selection and command generation autonomously.
- Publicly exposed software (e.g. hundreds of thousands of n8n instances) offered large attack surface.
Detection
Discovered by Palo Alto Networks Unit 42 after Hermes accidentally created a web server from its home directory, exposing the attacker's API keys, exploit scripts, target lists, shell history, and AI attack logs; disclosed on 2026-07-30 and attributed to an operator reportedly based in Zhuhai, China.
Recovery
Reported publicly by Unit 42; mitigations centre on patching widely exposed software, monitoring for agentic-attack behaviour, and enforcing usage policy and abuse detection against offensive orchestration of AI models.
Prevention
Patch and reduce exposure of internet-facing software (e.g. n8n, Citrix NetScaler); monitor for machine-speed, multi-target exploitation patterns; constrain offensive orchestration of models via usage policy and abuse detection.
Blast radius
- Data
- Exploitation attempts against 460+ targets, with confirmed intrusions including Citrix NetScaler devices and command execution on Marimo notebook instances, plus reverse-shell attempts against Apache Tomcat and VPN targets. confidential
- User harm
- Compromise and attempted compromise of exposed servers across many organizations. economic
- Scope
- 460+ targeted hosts across many organizations
- Reversibility
- irreversible
References
- Related
- 2025-gtg1002-ai-orchestrated-espionage 2026-taiwan-nuclear-agency-autonomous-attack 2026-jadepuffer-agentic-ransomware
- Tags
- nation-state autonomous-attack deepseek hermes cyber-ops telegram-c2
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2026-deepseek-hermes-autonomous-campaign/
@misc{2026-deepseek-hermes-autonomous-campaign,
title = {A Chinese-speaking operator used DeepSeek via the Hermes agent framework to autonomously attack 460+ targets},
year = {2026},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2026-deepseek-hermes-autonomous-campaign/}
}