Threat Actor Uses DeepSeek to Launch Autonomous Cyberattack Campaign

August 13, 2026
Threat Actor Uses DeepSeek to Launch Autonomous Cyberattack Campaign
IANS News

Key Points

  • A Chinese-speaking threat actor used DeepSeek and the Hermes Agent framework to launch an autonomous attack campaign against 460 targets, largely without human intervention.
  • The AI agent targeted vulnerabilities in products including Citrix NetScaler, Apache Tomcat, Langflow and n8n, ultimately obtaining authentication cookies from three compromised systems.
  • IANS Faculty recommend focusing on exposure management, identity controls and layered defenses, as autonomous attackers can now discover and exploit weaknesses at machine speed.

 

Threat Actor Uses DeepSeek to Launch Autonomous Cyberattack Campaign

A Chinese-speaking threat actor conducted autonomous, AI-driven attack campaigns using popular open-weight LLMs, according to Palo Alto’s Unit 42 threat researchers.

The actor, believed to be a lone individual, used DeepSeek and the Hermes Agent framework as an autonomous agent that exploited existing vulnerabilities against 460 targets, primarily in China and neighboring countries.

The model and agent used in the attacker’s setup were publicly and freely available and had no innate guardrails to hinder actions. The open-source Hermes Agent alongside the open-weight DeepSeek were selected by the attacker after earlier experimentation with Anthropic’s Claude and other LLMs, according to Unit 42.

In the attacks, the threat actor exploited vulnerabilities in Langflow, n8n Workflow Automation, Apache Tomcat, and Citrix NetScaler. The actor communicated with his framework via Telegram to begin the attacks but left the agent to itself to carry out the attacks autonomously.

Most of the automated attacks were unsuccessful, due to the targeted systems being unreachable or unresponsive to the agent, but the attacker’s tooling did manage to succeed in three exploits, resulting in exfiltrated NetScaler authentication cookies.

Unit 42 said it learned of the attacker due to a paper trail left behind from the Hermes Agent, exposing the actor’s tooling, targets and interaction history.


Big Picture

The limited success of this threat actor’s autonomous campaign is secondary to the actual concern for security teams -- the scale and scope of hacking operations an individual can execute using just a handful of tools.

Publicly available AI tools can be chained together to accomplish tasks, reducing work that used to take weeks into just hours.

"We’re likely to see a significant increase in the velocity of campaign actions such as enumerating exposed systems, researching current CVEs, acquiring public exploit code, selecting higher-value targets, and attempting exploitation. Security teams are going to need to adopt way more automation to combat this.”  Dave Shackleford, IANS Faculty.

The scale of the campaign was kept small not because of any special tooling or AI defenses, but from targeted organizations having segmentation and hardening measures, which made the AI give up at first resistance.

"As AI makes it cheaper and faster to find exploitable mistakes, fundamentals such as secure configuration, authentication, segmentation, and reducing unnecessary internet exposure become more important.”  Summer Craze Fowler, IANS Faculty.

 

IANS Faculty Recommendations

  • Shrink the externally exploitable window: Prioritize rapid patching and exposure management for internet-facing systems, especially newly disclosed vulnerabilities with public PoCs -- autonomous agents can now discover and operationalize these opportunities extremely quickly.
  • Strengthen configuration and identity controls: In this campaign, authentication requirements and safer configurations were enough to stop several autonomous exploitation attempts, reinforcing the value of secure defaults, least privilege and external attack-surface validation.
  • Build for failure: Assume autonomous attackers can rapidly test exploit paths at scale, and use layered controls so a single missed detection, vulnerability or misconfiguration does not lead to compromise.


Authors & Contributors

Tim McCarthy, Author - Security Reporter, IANS News

Summer Craze Fowler, IANS Faculty

Dave Shackleford, IANS Faculty

 

Although reasonable efforts will be made to ensure the completeness and accuracy of the information contained in our News & blog posts, no liability can be accepted by IANS or our Faculty members for the results of any actions taken by individuals or firms in connection with such information, opinions, or advice.

Subscribe to IANS Blog

Receive a wealth of trending cyber tips and how-tos delivered directly weekly to your inbox.

Please provide a business email.