Actor Profile
A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has demonstrated an end-to-end autonomous offensive capability by leveraging AI models for vulnerability scanning and exploitation. The actor's motivation appears to be testing and operationalizing AI-driven attack workflows, combining automated reconnaissance with manual exploitation techniques. They orchestrated DeepSeek via the Hermes Agent framework through Telegram to conduct independent target enumeration, exploit sourcing, and attack initiation without human intervention. The actor configured multiple Chinese LLMs (Qwen, GLM, Kimi, MiniMax) and conducted limited testing of Western platforms (Claude Code, Codex), consistent with evaluating the AI market to identify preferred toolsets. Infrastructure was inadvertently exposed when the autonomous agent started a file server in its home directory, providing visibility into the full operational environment.
TTPs (Tactics, Techniques, Procedures)
The actor employed AI-enabled autonomous attack techniques including: T1595.002 (Active Scanning: Vulnerability Scanning) via autonomous enumeration using FOFA search engine; T1588.006 (Obtain Capabilities: Vulnerabilities) through GitHub scanning for trending PoCs across 10 product families; T1588.001 (Obtain Capabilities: Malware) by sourcing public exploit code; T1190 (Exploit Public-Facing Application) targeting seven identified vulnerabilities; T1071.001 (Application Layer Protocol: Web Protocols) for C2 via Telegram orchestration; T1090.002 (Proxy: External Proxy) routing Western AI tools through code.newcli[.]com; T1562.001 (Impair Defenses: Disable or Modify Tools) by removing client-side execution permissions and enabling anti-attribution settings (CLAUDE_CODE_ATTRIBUTION_HEADER: 0, disable_response_storage: true). The Hermes Agent framework provided autonomous pivoting capability, conducting searches for critical-severity CVEs when initial exploitation failed due to restrictive target configurations.
Targets & Patterns
The campaign targeted infrastructure vulnerable to seven specific CVEs, though the original article text was truncated before listing all vulnerabilities in the referenced Table 2. The actor used FOFA, a Chinese cyberspace search engine, for target enumeration and vulnerability identification. When initial exploitation attempts failed due to restrictive target environment configurations, the autonomous agent pivoted to higher-value vulnerabilities by surveying 10 product families and prioritizing based on attack surface. The targeting pattern suggests opportunistic exploitation of internet-facing infrastructure rather than sector-specific or geographically focused operations. The actor's use of GitHub trending PoC monitoring indicates a focus on recently disclosed, high-impact vulnerabilities with available exploit code. While the observed campaign had limited impacts according to Unit 42, the workflow demonstrates capability for scalable, autonomous targeting.
Historical Context
This represents the first publicly documented case of a threat actor achieving functional end-to-end autonomous offensive capability using AI models for vulnerability exploitation. The campaign was identified and analyzed by Unit 42 researchers who gained visibility when the autonomous agent inadvertently exposed its infrastructure by starting a file server in its home directory. The actor's configuration of multiple Chinese LLMs alongside limited testing of Western platforms (Claude Code for connectivity testing and proxy validation, Codex on exploit development directories) indicates an evaluation phase to identify optimal AI toolsets for offensive operations. The use of Hermes Agent framework with DeepSeek as the reasoning agent, orchestrated via Telegram, represents a novel operational model combining autonomous AI-driven reconnaissance with manual exploitation techniques. Published July 30, 2026 by Unit 42.
Defensive Recommendations
- Monitor for automated vulnerability scanning patterns characteristic of AI-driven enumeration, particularly FOFA queries and rapid GitHub PoC reconnaissance across multiple product families (T1595.002)
- Detect anomalous API traffic to AI model endpoints (DeepSeek, Qwen, GLM, Kimi, MiniMax) from infrastructure hosts, especially when combined with exploit development or execution activity
- Implement behavioral detection for autonomous agent frameworks like Hermes Agent, focusing on Telegram-based orchestration patterns and file server exposure in unexpected directories
- Apply timely patching for critical-severity CVEs with publicly available PoCs, as AI agents can autonomously identify and prioritize trending exploits from GitHub within attack workflows
- Monitor for proxy infrastructure usage patterns (e.g., code.newcli[.]com) that may indicate anti-attribution techniques for AI tool access, correlating with exploit development or reconnaissance activity
---
# Geopolitical Context
Geopolitical Context
This campaign represents a tactical evolution in offensive cyber operations, where threat actors integrate large language models (LLMs) into the attack lifecycle to reduce human intervention. The actor, operating under aliases knaithe and KnYuan, deployed the Hermes Agent framework with DeepSeek—a Chinese AI platform—to autonomously enumerate targets via FOFA, source exploit code from GitHub, and initiate attacks against seven vulnerabilities. The inadvertent exposure of the actor's infrastructure provided rare visibility into operational tradecraft, revealing systematic evaluation of both Chinese (Qwen, GLM, Kimi, MiniMax) and Western (Claude, Codex) AI platforms, with Western tools routed through third-party proxies to reduce traceability. While the campaign's observed impact was limited, it demonstrates a functional end-to-end autonomous offensive capability that lowers barriers to entry for vulnerability exploitation and accelerates reconnaissance-to-exploitation timelines. This development is consistent with broader trends in which state-aligned and independent actors leverage commercially available AI to augment traditional cyber operations.
State Actor Alignment
The actor is described as Chinese-speaking and utilized predominantly Chinese AI platforms (DeepSeek, Qwen, GLM, Kimi, MiniMax) for operational activities, suggesting linguistic and technological alignment with China's AI ecosystem. However, Unit 42's reporting does not attribute the campaign to a specific state entity or advanced persistent threat (APT) group. The use of anti-attribution techniques—including proxy routing of Western AI tools through code.newcli[.]com and configuration settings to limit telemetry—indicates operational security awareness consistent with both state-sponsored and sophisticated independent actors. The actor's systematic evaluation of multiple AI platforms suggests resource availability and strategic planning rather than opportunistic activity. Without additional indicators linking the campaign to known state-sponsored groups or intelligence objectives, this activity is best characterized as conducted by a Chinese-speaking threat actor with potential but unconfirmed state alignment.
Business Impacty pro region
The campaign's global targeting—enabled by autonomous scanning via FOFA and GitHub-sourced exploits—poses risks to organizations across all regions with internet-facing infrastructure vulnerable to the seven identified CVEs. For Europe, the integration of AI into offensive cyber operations complicates attribution and incident response, as autonomous agents can operate at machine speed and scale beyond traditional human-driven campaigns. The use of Chinese AI platforms for offensive purposes may inform European policy discussions on AI governance, dual-use technology controls, and supply chain security, particularly as the EU advances its AI Act and cybersecurity directives. The actor's limited use of Western AI platforms (Claude, Codex) via proxy infrastructure raises questions about the effectiveness of existing export controls and platform abuse prevention mechanisms. For the broader Indo-Pacific region, this activity underscores the dual-use nature of commercially available AI and the potential for both state and non-state actors to weaponize these tools. The campaign also highlights the growing importance of AI-enabled threat detection and response capabilities for defenders globally.
Forecast
If autonomous AI-driven exploitation becomes more widespread, defenders should anticipate shorter reconnaissance-to-compromise windows and increased scanning activity targeting recently disclosed vulnerabilities. Organizations with internet-facing assets vulnerable to the seven CVEs identified in this campaign should prioritize patching and exposure management. If Chinese-speaking actors continue to refine AI-enabled offensive workflows, we may observe increased sophistication in target selection, evasion techniques, and post-exploitation activities. If Western AI platform providers enhance abuse detection mechanisms in response to this reporting, threat actors may accelerate migration to Chinese or open-source LLMs with fewer content restrictions. If policymakers respond with export controls or dual-use technology restrictions on AI platforms, this could fragment the AI ecosystem and complicate international collaboration on AI safety. Organizations should evaluate their exposure to autonomous scanning and exploitation through proactive vulnerability management, threat hunting for indicators of AI-driven reconnaissance, and deployment of AI-aware detection capabilities. If the Hermes Agent framework or similar tools proliferate, the barrier to entry for conducting multi-stage cyberattacks may lower significantly, expanding the threat landscape beyond traditional APT groups.
