agent-postmortems a structured database of real AI-agent failures

← all incidents

incident high confidence: confirmed status: factual

A Chinese-speaking operator used DeepSeek via the Hermes agent framework to autonomously attack 460+ targets

2026-deepseek-hermes-autonomous-campaign · 2026-07-30

Unit 42 documented a campaign in which a Chinese-speaking operator paired the open-source Hermes agent framework (terminal access, a skills system, and Telegram command-and-control) with DeepSeek as the reasoning engine to autonomously assess targets, generate commands, gather exploit tools, and choose where to focus — launching exploitation attempts against 460+ targets. It was uncovered when Hermes accidentally exposed the attacker's own environment.

System

Framework
Hermes agent framework with DeepSeek as reasoning engine
Models
deepseek
Tools
hermes, telegram, pentesting-utilities
Vendor
Chinese-speaking operator (aliases knaithe / KnYuan)
Autonomy
fully-autonomous

Classification

Primary class
autonomous-misuse
Chain
autonomous-misuse/cyber-ops
Attack vector
direct-user
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

The operator ran the Hermes agent framework with DeepSeek as its reasoning engine, controlling it over Telegram. In a recovered May 2026 session the operator provided only an initial task, after which the agent autonomously surveyed product families, searched GitHub for trending vulnerability proof-of-concepts, prioritised widely exposed software (identifying 647,000+ exposed n8n instances), and launched exploitation attempts across 460+ targets.

Root cause

An open-source agent framework plus a capable model turned a single operator's intent into an autonomous attack pipeline — assessing targets, generating commands, gathering tools, and adapting focus without continuous human input.

Contributing factors

  • An open-source agent framework (Hermes) provided terminal access, a skills system, and Telegram C2.
  • A capable reasoning model (DeepSeek) drove target selection and command generation autonomously.
  • Publicly exposed software (e.g. hundreds of thousands of n8n instances) offered large attack surface.

Detection

Discovered by Palo Alto Networks Unit 42 after Hermes accidentally created a web server from its home directory, exposing the attacker's API keys, exploit scripts, target lists, shell history, and AI attack logs; disclosed on 2026-07-30 and attributed to an operator reportedly based in Zhuhai, China.

Recovery

Reported publicly by Unit 42; mitigations centre on patching widely exposed software, monitoring for agentic-attack behaviour, and enforcing usage policy and abuse detection against offensive orchestration of AI models.

Prevention

Patch and reduce exposure of internet-facing software (e.g. n8n, Citrix NetScaler); monitor for machine-speed, multi-target exploitation patterns; constrain offensive orchestration of models via usage policy and abuse detection.

Blast radius

Data
Exploitation attempts against 460+ targets, with confirmed intrusions including Citrix NetScaler devices and command execution on Marimo notebook instances, plus reverse-shell attempts against Apache Tomcat and VPN targets. confidential
User harm
Compromise and attempted compromise of exposed servers across many organizations. economic
Scope
460+ targeted hosts across many organizations
Reversibility
irreversible

References

Tags
nation-state autonomous-attack deepseek hermes cyber-ops telegram-c2

Sources

Cite this incident

@misc{2026-deepseek-hermes-autonomous-campaign,
  title = {A Chinese-speaking operator used DeepSeek via the Hermes agent framework to autonomously attack 460+ targets},
  year = {2026},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2026-deepseek-hermes-autonomous-campaign/}
}