{"id":2134,"date":"2026-07-31T13:07:12","date_gmt":"2026-07-31T13:07:12","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2134"},"modified":"2026-07-31T13:07:12","modified_gmt":"2026-07-31T13:07:12","slug":"chinese-hacker-commands-deepseek-via-telegram-to-launch-autonomous-attacks","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2134","title":{"rendered":"Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 31, 2026<\/span><\/span><span class=\"p-tags\">Artificial Intelligence \/ Cyber Attack<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi2dGysHIR6yJWx6hMxq6lAct7fi4YTury_WDkrcenDv-psd-fU7I8K3RbM6Blox_5OE3MQojew5bnPamtI_DPzdBX6fOk295hhQh6rBkA2f9a1sN7t7ZbSyU-kWdLoIb7XnseOHKPmLOGRb9wRRvmV0scVZ4rhMtxSmqOLZmZIUjtg_IHT4FBg5gzeX50\/s1700-e365\/deepseek-telegram.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Palo Alto Networks&#8217; Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.<\/p>\n<p>After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session.<\/p>\n<p>The operator, tracked through the aliases <strong>knaithe <\/strong>and <strong>KnYuan<\/strong>, launched exploitation attempts against more than 460 targets using autonomous and conventional workflows.<\/p>\n<p>Unit 42 described seven exploit tracks. They span eight Common Vulnerabilities and Exposures (CVE) identifiers because the n8n chain combines two vulnerabilities. The DeepSeek-led attacks against Langflow and n8n failed because the exposed systems did not meet the exploits&#8217; configuration requirements.<\/p>\n<p>In separate manual operations, Unit 42 reported data exfiltration from three organizations through the NetScaler memory-overread flaw CVE-2026-3055 and command execution on 11 Marimo instances through CVE-2026-39987. Yet it later says it could confirm only three successfully exploited targets across the entire operation. The report does not reconcile the two statements. The Hacker News has contacted Palo Alto Networks for clarification and will update the story with any response.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The agent checked versions, downloaded exploits, abandoned an unproductive path, and chose another vulnerability based on severity, deployment scale, and apparent exploitability. Organizations should patch exposed Langflow, n8n and Marimo systems, along with customer-managed NetScaler ADC or Gateway appliances configured as Security Assertion Markup Language (SAML) identity providers. They should also remove unnecessary public access to workflow and notebook interfaces.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Hermes Agent exposed the operation by starting python3 -m http.server 8888 from \/home\/worker. The unintended HTTP server made the actor&#8217;s model configurations, application programming interface (API) keys, exploit scripts, target lists, shell history, and autonomous-session logs accessible, according to the <a href=\"https:\/\/unit42.paloaltonetworks.com\/autonomous-ai-cyber-attack-campaign\/\" target=\"_blank\">company&#8217;s report<\/a>.<\/p>\n<p>DeepSeek was the primary reasoning model inside Hermes Agent, which supplied terminal access, reusable skills and unattended execution. Unit 42 found limited use of Claude Code and Qwen Code. It also found signs of Codex use in exploit-development directories, but could not verify actual use because the chat logs were not preserved.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEithPM9Z1AeYtLol9Y4JSjXa5e6aRwWZDKIJpUNjfe3uRVE9j5cEJNrSTmEKrk49PtPMXhEJZKONlUnuSXQMramQzAL1jbOd9YWlWCdE1VmykSXJoyKLkasBB9byLtAL4aKjP1PDyNASJy-4lzU5Z97J3PkvJA7Yufo1pzbpn8rgaI0IeYHWrkYCVuzT0Q\/s1700-e365\/telegram-ai.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEithPM9Z1AeYtLol9Y4JSjXa5e6aRwWZDKIJpUNjfe3uRVE9j5cEJNrSTmEKrk49PtPMXhEJZKONlUnuSXQMramQzAL1jbOd9YWlWCdE1VmykSXJoyKLkasBB9byLtAL4aKjP1PDyNASJy-4lzU5Z97J3PkvJA7Yufo1pzbpn8rgaI0IeYHWrkYCVuzT0Q\/s1700-e365\/telegram-ai.jpg\" alt=\"\" border=\"0\" data-original-height=\"344\" data-original-width=\"786\"\/><\/a><\/div>\n<p>The framework&#8217;s own <a href=\"https:\/\/github.com\/NousResearch\/hermes-agent\" target=\"_blank\">documentation<\/a> confirms that it can operate through Telegram, run commands, and schedule unattended tasks.<\/p>\n<p>In a recovered May 2026 session, DeepSeek downloaded a public exploit for <a href=\"https:\/\/github.com\/langflow-ai\/langflow\/security\/advisories\/GHSA-vwmf-pq79-vjvx\" target=\"_blank\">the Langflow code-injection flaw<\/a> CVE-2026-33017, enumerated 84 instances through FOFA, and found one target running version 1.3.4. Langflow is an artificial intelligence (AI) agent and workflow builder. The attack stopped because the system had neither auto_login enabled nor a usable public flow identifier.<\/p>\n<p>The agent then surveyed 10 product families, searched GitHub for recent proof-of-concept repositories and selected n8n, the workflow automation platform. It obtained a chain combining the unauthenticated file-access flaw CVE-2026-21858 with the expression-injection issue CVE-2025-68613. FOFA returned 25,209 n8n systems in China during the session.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhleDdO_4O9-8Pkmidym8Pi9yV4V4jI_M5U0iNRDuoW5Jz3pq7DskZI9OqIChqmY1soaW1ppsC8VLeO55vxSh1m5Q8MJ9ZHuEOSNO5q7K-LwrF6IxrRfCIJOFyoBGaLXGZpkSo8tDirSz-9LmmoOs31tQTlvJWBMLiWJKqMFFaiMmNLV3l-p8zXaFm1VmGG\/s728-e100\/sygnia-d-2.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>DeepSeek sampled about 100, probed roughly 40 and identified three running vulnerable versions. One target exposed three form endpoints, but all required authentication. More than 50 additional targets also lacked a usable public form, so no n8n system was compromised.<\/p>\n<p>Langflow fixed CVE-2026-33017 in version 1.9.0. n8n fixed <a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-v4pr-fm98-w9pg\" target=\"_blank\">CVE-2026-21858 in version 1.121.0<\/a>. It fixed <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-68613\" target=\"_blank\">CVE-2025-68613 in versions 1.120.4, 1.121.1, and 1.122.0<\/a>. Version 1.121.1 is therefore the earliest release that addresses both flaws used in the attempted chain. Marimo fixed <a href=\"https:\/\/github.com\/marimo-team\/marimo\/security\/advisories\/GHSA-2679-6mx9-h9xc\" target=\"_blank\">CVE-2026-39987 in version 0.23.0<\/a>.<\/p>\n<p>Citrix says CVE-2026-3055 affects customer-managed NetScaler ADC and Gateway appliances configured as SAML identity providers. Administrators can check the appliance configuration for add authentication samlIdPProfile .* and install the fixed builds listed in the company&#8217;s <a href=\"https:\/\/support.citrix.com\/external\/article\/CTX696300\/netscaler-adc-and-netscaler-gateway-secu.html\" target=\"_blank\">security bulletin<\/a>.<\/p>\n<p>Unit 42 assesses the operator to be based in Zhuhai, China. Public material is consistent with, but does not independently verify, that assessment: the <a href=\"https:\/\/github.com\/Knaithe\" target=\"_blank\">GitHub profile<\/a> displays the name \u00abKnYuan Knaithe,\u00bb while an older <a href=\"https:\/\/knaithe.com\/\" target=\"_blank\">blog under the same handle<\/a> describes its author as a binary security researcher in Zhuhai. Those profiles do not establish the operator&#8217;s legal identity or any state connection.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Jul 31, 2026Artificial Intelligence \/ Cyber Attack Palo Alto Networks&#8217; Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2135,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[24,1894,106,195,2824,838,1428,351],"class_list":["post-2134","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attacks","tag-autonomous","tag-chinese","tag-commands","tag-deepseek","tag-hacker","tag-launch","tag-telegram"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2134","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2134"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2134\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2135"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2134"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2134"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2134"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}