Skip to content

Chinese Attacker Exploits DeepSeek via Telegram for Autonomous Cyberattacks

The Point: DeepSeek was deployed by an attacker through the Hermes Agent Framework to autonomously compromise internet-facing systems without requiring further operator involvement.

Palo Alto Networks documented that a Chinese-speaking attacker leveraged the DeepSeek language model via the Hermes Agent Framework to execute autonomous cyberattacks. Following an initial instruction via Telegram, the agent independently identified targets and selected exploits from publicly available resources.

Palo Alto Networks’ Unit 42 identified a Chinese-speaking threat actor who utilized DeepSeek through the open-source infrastructure of the Hermes Agent Framework to conduct automated cyberattacks. The attacker sent an initial instruction via Telegram, upon which the agent autonomously identified internet-facing targets and selected from publicly available exploits.

The distinctive aspect of the incident: after the first Telegram instruction, no further operator intervention was necessary. The system operated completely autonomously. Researchers could not detect any further manual intervention throughout the entire session. The responsible attacker is tracked under the aliases knaithe and KnYuan.

For CISOs, this case underscores the risk of well-resourced threat actors instrumentalizing open-source AI agents. The combination of large language models and automated agent capabilities significantly lowers the barrier for scaled attacks—particularly given that DeepSeek is freely available and Hermes Agent is provided as open source. Organizations should intensify monitoring for anomalies in exploit deployment and unusual scanning patterns.


Source: thehackernews.com · Published 31 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: