Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
A Chinese-speaking threat actor has deployed AI models to conduct autonomous cyberattacks, leveraging tools like DeepSeek and Hermes Agent to identify and exploit vulnerabilities in infrastructure. The actor, known as knaithe or KnYuan, used FOFA for asset discovery and targeted seven critical vulnerabilities, including CVE-2026-33017 and CVE-2026-21858. While some attacks failed due to target-side configurations, the campaign demonstrates a functional end-to-end autonomous offensive capability. Palo Alto Networks offers protections through Cortex XDR, XSIAM, and Next-Generation Firewall.
Executive Summary
Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact.
The actor, operating under the aliases knaithe and KnYuan, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator. They orchestrated this operator via Telegram for the following activities:…