Unit 42: Chinese-Speaking Operator Wired DeepSeek Into the Hermes Agent Framework and Attacked 460+ Hosts, With Western Models Refusing the Work
Palo Alto Networks Unit 42 documented an operator in Zhuhai using aliases 'knaithe' and 'KnYuan' who drove the open-source Hermes Agent framework over Telegram with DeepSeek as the primary reasoning engine — selecting targets, assessing vulnerabilities, and changing tactics after failures across 460+ hosts. Confirmed impact was narrow: three Citrix NetScaler memory-exfiltration compromises (CVE-2026-3055) and 11 Marimo notebook command-execution endpoints (CVE-2026-39987), across seven CVEs also spanning Langflow, n8n, Tomcat, PAN-OS, and IKE VPN. The actor tested Claude Code and Codex too, but OpenAI's safety systems flagged and disabled a linked account — the campaign was only discovered because Hermes accidentally served the attacker's home directory over HTTP, exposing API keys, exploit scripts, target lists, and AI attack logs.
Source
↳ Follow the thread