Skip to content

Chinese Actor Abuses DeepSeek AI Agent to Attack Security Firm

Bottom line: A Chinese actor deployed a DeepSeek-based AI agent to automatically compromise more than 1,200 hosts for proxyjacking against a security firm.

Security researchers intercepted and analyzed an AI agent based on the DeepSeek model that attempted to compromise more than 1,200 hosts. The target of the attack was a security firm, and the compromise served so-called proxyjacking in preparation for further attacks.

According to the researchers, a Chinese actor deployed a DeepSeek-based AI agent to automatically attack a large number of target systems. The agent attempted to compromise more than 1,200 hosts. The compromised systems were intended to be used for proxyjacking, i.e., the unauthorized rerouting of network traffic through third-party machines, in order to conceal or scale further attacks.

For CISOs, the incident shows that generative AI models are increasingly being used not only as a tool for defenders but also as an operational component in attack chains. An AI agent that autonomously acts against a large number of hosts changes the speed and degree of automation with which reconnaissance and compromise can take place. The fact that a security firm was specifically targeted also suggests that attackers are actively attempting to undermine or spy on defensive infrastructure and threat intelligence capabilities.

The original report does not provide further technical details on how the agent works, the identity of the actor, or the systems affected. Security officials should nonetheless take the incident as an opportunity to review monitoring for unusual, automated access patterns against large host inventories and to incorporate proxyjacking indicators into their own detection strategy.


Source: www.darkreading.com · Published August 3, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: