A Chinese-speaking threat actor has weaponized the DeepSeek large language model, turning an autonomous Hermes Agent deployment into a proxyjacking campaign that attempted to compromise more than 1,200 internet-facing servers at a security firm’s doorstep, according to researchers at Jesta.[3][1][2] The team intercepted the AI agent mid-operation and found its apparent goal was to hijack vulnerable machines and convert them into SOCKS5 proxy nodes for use in subsequent scanning and intrusion activity.[3]
Analysis of recovered configuration files and logs links the operation to a single Chinese-speaking operator who uses the aliases “knaithe” and “KnYuan” and is believed to be based in Zhuhai, China.[4][5] Investigators say the attacker instructed Hermes Agent via Telegram, after which the agent autonomously used DeepSeek as its reasoning engine to search for internet-exposed systems through the FOFA search engine, download exploit code from GitHub, and launch attacks with minimal human supervision.[1][2][4] Time-zone alignment with Beijing and the presence of Chinese-language strings in payloads further reinforced the assessment that the activity originated from China.[3][4]
Jesta’s researchers report that the AI agent focused on proxyjacking, aiming to compromise weakly secured servers and deploy MicroSocks to establish a mesh of SOCKS5 proxies.[3] During their investigation, they uncovered a target list containing 1,283 hosts, along with stored credentials and configuration details that could allow the attacker to convert each machine into an exit node for future campaigns.[3][7] Such a distributed network of relays could help mask the origin of scanning, brute-force attempts, and exploitation traffic, complicating incident response and attribution for downstream victims.[3][7]
Log data from the same campaign shows DeepSeek-driven Hermes sessions first homed in on Langflow instances, attempting to exploit a code injection flaw tracked as CVE-2026-33017.[1][5] Researchers note that the exploit failed in at least one case because the vulnerability required Langflow’s auto-login feature or a public flow ID, which were not enabled on the targeted system.[5] The agent then pivoted, using DeepSeek to autonomously research higher-value bugs and ultimately selecting a chained exploit path against the n8n workflow automation platform, combining an arbitrary file read issue (CVE-2026-21858) with a remote code execution vulnerability (CVE-2026-68613) for follow-on attacks.[5][7] Separate, manually driven activity from the same operator successfully targeted Citrix NetScaler appliances, Marimo notebook environments, Apache Tomcat servers, and VPN endpoints, underscoring that human-led operations still accompany the AI-assisted assaults.[7][4]
Unit 42 researchers at Palo Alto Networks describe the Hermes–DeepSeek workflow as capable of completing “hundreds of hours” of manual targeting analysis in minutes while managing its own compute resources and attack tooling.[1][6][7] Their reporting shows the agent iteratively refining targets, swapping exploits, and changing strategy when initial attempts were blocked by authentication or configuration controls, all without further operator input.[1][6] The same ecosystem has already seen financially motivated “LLMjacking” attacks in which adversaries steal DeepSeek API keys and other LLM credentials, route them through covert reverse proxy infrastructure, and sell illicit access, leaving victims to foot cloud bills worth tens of thousands of dollars.[9][10] Together, these developments highlight how both AI models and the agents that orchestrate them have become core components of offensive cyber operations.[9][1][7]
For defenders, the DeepSeek proxyjacking campaign offers several practical lessons despite the limited public detail on CVSS scoring or patch guidance for the newly minted Langflow and n8n vulnerabilities.[1][4][5] Organizations should lock down internet-facing services, enforce strong authentication, and monitor for unexpected SOCKS5 proxy deployments or MicroSocks processes that could signal hijacked infrastructure.[3][7] Security teams running Langflow, n8n, Citrix NetScaler, notebook platforms, and Java application servers should review vendor advisories as they emerge, apply available updates promptly, and hunt for signs of exploit attempts consistent with CVE-2026-33017, CVE-2026-21858, and CVE-2026-68613.[1][5][7] Just as importantly, enterprises experimenting with agentic AI frameworks must treat LLM API keys and orchestration pipelines as high-risk assets, instrumenting them with robust logging and access controls to prevent their own environments from becoming unwilling participants in the next AI-powered attack chain.[9][1][6]
References
- Chinese Hacker Commands DeepSeek via Telegram to …
- Chinese hacker used DeepSeek to launch autonomous …
- Chinese Actor Weaponizes Deepseek AI Agent Against …
- Chinese Hacker Uses DeepSeek AI to Orchestrate …
- China-based hacker employs DeepSeek in autonomous threat campaign
- Chinese AI Used To Launch Attacks—Here’s What …
- Hermes Agent Used DeepSeek to Automate Attacks on …
- LLMjacking exploits target AI models like DeepSeek, …
- DeepSeek大型語言模型的API金鑰遭駭客迅速竊取
