Researchers at Palo Altoβs Unit 42 have uncovered a sophisticated cyber campaign orchestrated by Chinese-speaking threat actors who integrated artificial intelligence to automate offensive operations. The attackers utilized the DeepSeek model as a reasoning engine, tethering it to an open-source tool known as the Hermes Agent. This setup allowed the AI to perform complex tasks such as identifying network vulnerabilities, selecting appropriate exploit code, and launching attacks with minimal human intervention. According to Security Affairs, this discovery marks a significant shift in threat actor methodology, as the AI managed the lifecycle of the intrusion from initial reconnaissance to target selection.
Evidence of this operation was inadvertently exposed when the threat actor misconfigured a file server, leaving sensitive logs, exploit scripts, and session history accessible. This oversight provided investigators with a comprehensive view of how the AI operated within the Hermes framework. While DeepSeek served as the primary intelligence driver, the attackers also experimented with several other models, including Qwen, GLM, Kimi, and MiniMax. In contrast to their direct API usage of Chinese-hosted models, the operators attempted to obfuscate their interaction with Western platforms like Claude Code by routing traffic through third-party proxies, suggesting a strategic effort to mask their reconnaissance activities on foreign infrastructure.
This incident highlights a growing trend where malicious entities leverage large language models to lower the barrier to entry for complex cyber operations. By using the Hermes Agent to handle terminal access and command-and-control functions while relying on DeepSeek to handle decision-making and vulnerability assessment, the actors demonstrated a highly efficient, automated workflow. The researchers noted that this use of AI represents an emerging threat landscape where speed and machine-led reasoning accelerate the discovery and exploitation of critical systems, forcing security teams to rethink their defensive strategies against non-human-led intrusion attempts.
Reader Discussion & Insights