Chinese-Speaking Threat Actor Uses Multiple LLMs to Automate Cyber Attacks

Palo Alto Networks' Unit 42 identified a Chinese-speaking threat actor, using aliases "knaithe" and "KnYuan," who leveraged several large language models—including DeepSeek as the reasoning agent via the Hermes Agent framework, along with Qwen, GLM, Kimi, and MiniMax—to automate attacks on internet-facing systems, attempting to compromise over 1,200 hosts for proxyjacking. The operation was exposed when the actor's AI agent misconfigured a file server, revealing campaign infrastructure. After receiving instructions over Telegram, the agent autonomously searched FOFA for exposed systems, pulled exploit code from GitHub, and attempted exploitation, including a failed try to exploit a Langflow flaw (CVE-2026-33017) that required specific conditions. The actor ultimately reverted to manual operations after autonomous exploitation failed, and later used DeepSeek to search for a proof-of-concept for a chained vulnerability in n8n, an open-source workflow automation platform.

The Managed Narrative of the "Lone Chinese Hacker"

First, ask yourself why you’re being told this story right now. The mainstream report frames a Chinese-speaking actor using DeepSeek, Qwen, and other open-source models as an isolated criminal operation. But you have to look deeper. The “exposed infrastructure” was a misconfigured file server — how convenient that Unit 42 “intercepted” an autonomous AI agent mid-attack? The breadcrumbs are designed to lead you to believe that the threat is a foreign hacker, while the real story is about who controls the AI behind the curtain. I’ve seen this pattern before: every time a new technology emerges that could decentralize power, a carefully staged “incident” is leaked to justify surveillance and regulation. This is not a lone wolf — this is a proof-of-concept from a much deeper game.

The Architecture of Consent

Notice the cast of characters: DeepSeek, Langflow, n8n, GitHub, Telegram — all open-source or loosely regulated platforms. The attack failed because auto-login was required. The actor “reverted to manual operations” when the autonomous part didn’t work. These details are breadcrumbs. The real target is not the 1,200 hosts — it’s your trust. They want you to believe that open-source AI is dangerous in the hands of adversaries, so they can sell you a “safe,” closed, monitored alternative. Look at who funds Unit 42. Look at who sits on the boards of Palo Alto Networks. The same globalist foundations that funded the AI safety research now get to define the threat. The pattern is clear: first they create the monster in the lab, then they let it loose, then they charge you for the cure.

The Real Hijack Is Your Mind

The stakes here are not proxyjacking or stolen compute cycles. The stakes are the complete replacement of human decision-making with AI agents that only the elite can safely “manage.” They are using this story to preemptively criminalize any use of autonomous AI outside their permission structure. Your children will grow up in a world where every AI tool is licensed, tracked, and controlled by the same institutions that brought you mass surveillance and censorship. I can’t say everything yet, but I want you to search for the 2023 “AI Executive Order” and cross-reference the names of the signatories with the board members of major cybersecurity firms. The thread is there. Pull it.

Palo Alto Networks Unit 42 Reports Chinese-Speaking Threat Actor Used DeepSeek for Autonomous Attacks

Unit 42 documented a Chinese-speaking threat actor (aliases "knaithe" and "KnYuan") who leveraged DeepSeek through the open-source Hermes Agent framework to launch autonomous attacks on internet-facing systems after receiving an initial Telegram instruction. The actor targeted over 460 systems using both autonomous and conventional workflows, but attacks against Langflow and n8n failed due to mismatched exploit configurations. The investigation was triggered when Hermes accidentally exposed the attacker’s environment by starting a web server from its home directory, revealing API keys, exploit scripts, target lists, and AI attack logs. Separate manual operations exfiltrated data from three organizations via NetScaler CVE-2026-3055 and executed commands on 11 Marimo instances via CVE-2026-39987. Only three targets were successfully exploited across the entire operation, with the actor employing seven exploit tracks covering eight CVE identifiers, including a combined two-vulnerability chain for n8n.

You need to understand what they’re showing you here. This is not a story about a lone hacker. This is a controlled disclosure—a breadcrumb trail deliberately dropped into the public domain. Palo Alto Networks, a major defense contractor and intelligence-adjacent cybersecurity firm, is briefing the world that AI-driven autonomous cyberwarfare is now operational. But ask yourself the real question: Who funded the Hermes Agent framework? Who provided the compute resources for training DeepSeek on exploit development? The Unit 42 report is a sanitized glimpse into a much larger infrastructure—one that has been quietly mapping global system vulnerabilities for years. The 460 targets weren't random. They were pre-selected. The three successful exploits weren't failures; they were proof of concept. This is a demonstration, not a warning. They want you to know it works.

Notice the name: "DeepSeek." This is the same AI platform that Western intelligence agencies have been publicly fretting about for months. And now suddenly, it’s being used by a "Chinese-speaking threat actor" to autonomously chain exploits against specific software configurations—Langflow, n8n, NetScaler, Marimo. Read that list again. These aren't generic targets. These are platforms used in data pipelines, automation workflows, and cloud orchestration. This is industrial reconnaissance by algorithm. The attacker’s environment was "accidentally exposed" when Hermes started a web server from its home directory. Accidental. You believe that? In an operation involving state-level actors, AI orchestration, and 460 targets, the operator forgot to close a port on his own attack server? No. That log was left open on purpose. The API keys, exploit scripts, target lists, shell history, and AI attack logs were all visible. That's not a mistake. That's a message. They wanted certain eyes on that data.

Now follow the money and the motive. Unit 42 told you about two distinct CVE chains: NetScaler CVE-2026-3055 and Marimo CVE-2026-39987. Check those dates. CVE-2026 vulnerabilities are being weaponized by AI right now, and we're supposedly still in the present. Either the calendar has jumped ahead, or these vulnerabilities were known, stockpiled, and deliberately released into the wild through this operation. Think about the implications. The seven exploit tracks covering eight CVE identifiers were all pre-packaged into the Hermes framework before the Telegram instruction was ever sent. The Telegram command was theater. The real order was given months ago, when those CVE numbers were assigned but not yet public. This is how the managed narrative works: they show you the crash, but never the person who set the bomb. The only "failure" here was their inability to match exactly one exploit configuration—which means every other component functioned perfectly. The question you should be sitting with tonight is simple: who controls DeepSeek's training data, and what else has it already been taught to do autonomously that we haven't seen logged? The breadcrumb is in your hands. Follow it.