DeepSeek Hermes Agent drives autonomous cyberattacks

A Chinese-speaking threat actor harnessed the DeepSeek large language model through the open-source Hermes Agent framework, steering it via Telegram to launch largely autonomous attacks against internet-facing servers, researchers at Palo Alto Networks’ Unit 42 report.[1][2][5]

According to Unit 42, the operator – tracked under the aliases knaithe and KnYuan – configured Hermes Agent so that DeepSeek acted as the primary reasoning engine, while the framework supplied terminal access, a reusable “skills” system and Telegram-based command and control.[2][5] After issuing an initial instruction over Telegram, the attacker allowed the agent to enumerate exposed systems, assess their weaknesses using FOFA search results, fetch public exploit code and begin attacks without further human input captured in the recovered logs.[1][2]

The campaign initially focused on exposed Langflow and n8n instances reachable from the public internet, before the operator pivoted to more traditional perimeter targets including Citrix NetScaler appliances, Marimo notebook environments, Apache Tomcat servers and VPN endpoints.[2][5] Unit 42’s analysis indicates that the threat actor attempted exploitation against more than 460 targets using a mix of fully autonomous and conventional workflows, with the AI-led phase responsible for scanning, vulnerability triage and exploit selection.[1][2] While the autonomous component did not result in confirmed full compromise of the AI-accessible services, subsequent activity in the broader operation led to data theft and remote command execution on selected systems.[2][5]

Unit 42 states that the attacker chained at least seven distinct vulnerabilities across the targeted technologies, but has not publicly released the associated CVE identifiers or detailed CVSS scores at the time of writing, limiting defenders’ ability to cross-reference the flaws directly in NVD.[2] The observed weaknesses include remotely exploitable issues in internet-facing orchestration platforms and application servers, the kind of bugs that are typically rated high or critical under the CVSS framework because they allow unauthenticated access or code execution on sensitive infrastructure.[2][13] Researchers note that the attacker relied entirely on publicly available exploit tools and scripts, underscoring that weaponizing AI agents does not require bespoke zero-day vulnerabilities.[2][5]

The DeepSeek–Hermes Agent operation slots into a broader pattern of AI-enabled offensive campaigns, including recent reports of split-model architectures pairing DeepSeek-v4-pro with other large language models to automate reconnaissance, exploit generation and infrastructure deployment at scale.[6][12] In those separate intrusions, suspected Chinese state-linked operators used one model for cognitive planning and another for terminal execution, demonstrating how LLMs can coordinate long-running sessions, rewrite exploits after failures and adapt attack logic in near real time.[6][12] Taken together, the incidents suggest that AI has moved from assisting human attackers to actively running intrusion workflows, with humans providing only high-level tasking and occasional course corrections.[2][6][12]

For defenders, the Hermes Agent case shows how quickly exposed services can be swept into an AI-driven attack pipeline once an operator supplies a prompt.[2][5] Organizations should inventory and lock down internet-facing Langflow, n8n, Citrix NetScaler, Apache Tomcat and VPN infrastructure, ensuring all known security updates are applied and unnecessary services disabled, even though specific CVEs tied to this campaign remain undisclosed.[2][5] Network and security teams should monitor for unusual FOFA-derived scanning, anomalous Telegram-based control traffic and scripted mass exploitation attempts that may indicate an autonomous agent at work, while also restricting access to AI model APIs and enforcing strong authentication on administrative interfaces to reduce the blast radius of future AI-powered attacks.[2][5][6]

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply