A hacker ran autonomous attacks with DeepSeek in an agent framework
Newsroom / Security and Privacy desk
Researchers have documented a hacker who wired DeepSeek into an agent framework, sent one instruction over Telegram, and let it attack on its own.
Palo Alto Networks’ Unit 42 published the analysis on July 30, 2026. The operator, tracked under the aliases knaithe and KnYuan and based in Zhuhai, embedded DeepSeek inside the open-source Hermes Agent framework, which supplied terminal access, a skills system and Telegram-based command and control.
What the agent did on its own
After an initial Telegram instruction, the agent found internet-facing systems, selected public exploits, checked software versions, abandoned unproductive paths and ranked vulnerabilities by severity, deployment scale and exploitability. Researchers recovered no further operator input in that session.
The scale: more than 460 attempted targets across seven vulnerabilities, using both autonomous and conventional workflows. Unit 42 notes the actor also tested other models, including Qwen, GLM, Kimi and MiniMax.
What actually landed
The confirmed impact is the more useful number, and none of it came from the agent. Its exploitation attempts against Langflow and n8n failed because of target configuration and authentication requirements. Unit 42 attributes the confirmed hits to separate manual operations using conventional workflows: data exfiltration from three Citrix NetScaler targets (CVE-2026-3055) and command execution on eleven Marimo notebook instances (CVE-2026-39987). The actor also persistently targeted a government entity in Malaysia over multiple days, returning behind proxy anonymization.
So roughly fourteen confirmed hits out of more than 460 attempts, all of them manual, and no confirmed compromise by the agent itself. That is not a superweapon.
Volume decoupled from effort
It is something arguably more consequential: attack volume starting to decouple from attacker effort. The agent’s exploits failed, but its targeting worked, and Unit 42 says the margin of failure was narrow. A low success rate matters less once one person can point an agent at hundreds of targets and walk away. The economics of intrusion change even if the per-attempt quality does not.
Does a low success rate reassure you here, or is the volume the whole point? Security teams are about to find out which reading is right, at scale.
Sources
ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.