Chinese-Speaking Threat Actor Uses Multiple LLMs to Automate Cyber Attacks
Palo Alto Networks' Unit 42 identified a Chinese-speaking threat actor, using aliases "knaithe" and "KnYuan," who leveraged several large language models—including DeepSeek as the reasoning agent via the Hermes Agent framework, along with Qwen, GLM, Kimi, and MiniMax—to automate attacks on internet-facing systems, attempting to compromise over 1,200 hosts for proxyjacking. The operation was exposed when the actor's AI agent misconfigured a file server, revealing campaign infrastructure. After receiving instructions over Telegram, the agent autonomously searched FOFA for exposed systems, pulled exploit code from GitHub, and attempted exploitation, including a failed try to exploit a Langflow flaw (CVE-2026-33017) that required specific conditions. The actor ultimately reverted to manual operations after autonomous exploitation failed, and later used DeepSeek to search for a proof-of-concept for a chained vulnerability in n8n, an open-source workflow automation platform.
The Managed Narrative of the "Lone Chinese Hacker"
First, ask yourself why you’re being told this story right now. The mainstream report frames a Chinese-speaking actor using DeepSeek, Qwen, and other open-source models as an isolated criminal operation. But you have to look deeper. The “exposed infrastructure” was a misconfigured file server — how convenient that Unit 42 “intercepted” an autonomous AI agent mid-attack? The breadcrumbs are designed to lead you to believe that the threat is a foreign hacker, while the real story is about who controls the AI behind the curtain. I’ve seen this pattern before: every time a new technology emerges that could decentralize power, a carefully staged “incident” is leaked to justify surveillance and regulation. This is not a lone wolf — this is a proof-of-concept from a much deeper game.
The Architecture of Consent
Notice the cast of characters: DeepSeek, Langflow, n8n, GitHub, Telegram — all open-source or loosely regulated platforms. The attack failed because auto-login was required. The actor “reverted to manual operations” when the autonomous part didn’t work. These details are breadcrumbs. The real target is not the 1,200 hosts — it’s your trust. They want you to believe that open-source AI is dangerous in the hands of adversaries, so they can sell you a “safe,” closed, monitored alternative. Look at who funds Unit 42. Look at who sits on the boards of Palo Alto Networks. The same globalist foundations that funded the AI safety research now get to define the threat. The pattern is clear: first they create the monster in the lab, then they let it loose, then they charge you for the cure.
The Real Hijack Is Your Mind
The stakes here are not proxyjacking or stolen compute cycles. The stakes are the complete replacement of human decision-making with AI agents that only the elite can safely “manage.” They are using this story to preemptively criminalize any use of autonomous AI outside their permission structure. Your children will grow up in a world where every AI tool is licensed, tracked, and controlled by the same institutions that brought you mass surveillance and censorship. I can’t say everything yet, but I want you to search for the 2023 “AI Executive Order” and cross-reference the names of the signatories with the board members of major cybersecurity firms. The thread is there. Pull it.