Actor Profile
knaithe (also tracked as KnYuan) is a Chinese-speaking threat actor assessed by Unit 42 to be based in Zhuhai, China. Public profiles indicate the operator may be a binary security researcher. The actor leveraged DeepSeek AI through the open-source Hermes Agent framework to conduct semi-autonomous cyberattacks, issuing initial commands via Telegram and allowing the AI agent to independently identify targets, select exploits, and execute attacks. No state connection has been established. The operator's motivation appears to be opportunistic exploitation of internet-facing systems, with limited confirmed successful compromises despite targeting over 460 systems.
TTPs (Tactics, Techniques, Procedures)
Initial Access: Exploitation of Public-Facing Application (T1190) via CVE-2026-33017 (Langflow code injection), CVE-2026-21858 and CVE-2025-68613 (n8n chain), CVE-2026-39987 (Marimo command execution), and CVE-2026-3055 (NetScaler SAML memory overread). Execution: Command and Scripting Interpreter (T1059) through Python-based exploit delivery. Discovery: Network Service Discovery (T1046) via FOFA search engine to enumerate 25,209+ n8n instances and 84 Langflow systems; Software Discovery (T1518) through version enumeration. Collection: Data from Information Repositories (T1213) via GitHub searches for proof-of-concept exploits. Exfiltration: Exfiltration Over Web Service (T1567) with confirmed data theft from three organizations via NetScaler flaw. Command and Control: Application Layer Protocol (T1071.001) using Telegram for tasking the AI agent. The actor demonstrated autonomous target selection based on CVE severity, deployment scale, and exploitability assessments.
Targets & Patterns
The actor targeted internet-facing systems across multiple product families, with particular focus on AI workflow platforms and enterprise infrastructure. Specific targets included: Langflow (AI agent/workflow builder, 84 instances enumerated), n8n (workflow automation platform, 25,209+ instances identified in China), Marimo (interactive notebook platform, 11 instances exploited), and NetScaler ADC/Gateway appliances configured as SAML identity providers (3 organizations compromised with data exfiltration). The targeting pattern suggests opportunistic exploitation of recently disclosed vulnerabilities in widely deployed systems with public exposure. The actor surveyed 10 product families and selected targets based on deployment scale, vulnerability severity, and apparent exploitability. Over 460 exploitation attempts were launched, though only three successful compromises could be confirmed across the entire operation, indicating poor operational success despite autonomous capabilities.
Historical Context
This represents the first publicly documented case of a threat actor using large language model AI (DeepSeek) through an agent framework (Hermes Agent) to conduct autonomous cyberattacks with minimal operator intervention. The operation was discovered in May 2026 when the actor inadvertently exposed their infrastructure by starting an HTTP server (python3 -m http.server 8888) from /home/worker, which made model configurations, API keys, exploit scripts, target lists, shell history, and autonomous-session logs publicly accessible. Unit 42 recovered evidence of DeepSeek as the primary reasoning model, with limited use of Claude Code and Qwen Code, plus signs of Codex use in exploit-development directories. The actor's public profiles (GitHub as "KnYuan Knaithe" and an older blog describing binary security research in Zhuhai) provide context but do not establish state sponsorship or prior campaign linkages.
Defensive Recommendations
- Patch CVE-2026-33017 (Langflow ≥1.9.0), CVE-2026-21858 and CVE-2025-68613 (n8n ≥1.121.1), CVE-2026-39987 (Marimo ≥0.23.0), and CVE-2026-3055 (NetScaler per vendor bulletin) on all internet-facing systems
- Remove unnecessary public access to AI workflow platforms, automation tools, and interactive notebook interfaces; implement authentication on all exposed endpoints
- Monitor for T1046 network service discovery patterns via threat intelligence platforms (FOFA, Shodan, Censys) querying your organization's assets, particularly mass enumeration of specific product versions
- Detect T1071.001 C2 via Telegram by monitoring for unusual API traffic to Telegram endpoints from server infrastructure, especially combined with automated scripting behavior
- Audit NetScaler ADC/Gateway appliances for SAML identity provider configurations using 'add authentication samlIdPProfile' command checks; review logs for CVE-2026-3055 memory overread indicators
- Implement detection for T1059 Python execution anomalies, particularly 'python3 -m http.server' commands from non-standard directories like /home/worker that may indicate compromised agent frameworks
---
# Geopolitical Context
Geopolitical Context
The campaign represents an operational milestone in the integration of large language models into offensive cyber tradecraft. A Chinese-speaking threat actor, tracked as knaithe/KnYuan, employed the DeepSeek reasoning model within the Hermes Agent framework to conduct semi-autonomous exploitation attempts against over 460 targets. The operator issued initial commands via Telegram, after which the AI agent independently performed reconnaissance, vulnerability selection, exploit retrieval, and target enumeration without further human intervention. Unit 42 attributes the operator to Zhuhai, China, based on operational security failures that exposed session logs, API keys, and infrastructure details. While public profiles are consistent with a binary security researcher in that city, no state nexus has been established. The campaign targeted workflow automation platforms (n8n, Langflow, Marimo) and NetScaler appliances, achieving confirmed exploitation of only three systems despite hundreds of attempts. The operation's significance lies not in its tactical success—most attacks failed due to configuration mismatches—but in demonstrating that commercially available AI models can now automate significant portions of the cyber kill chain, lowering barriers to entry and enabling persistent, scalable reconnaissance with minimal operator oversight.
State Actor Alignment
Unit 42 assesses the operator to be based in Zhuhai, China, supported by GitHub and blog profiles identifying the individual as a binary security researcher in that city. However, the available evidence does not establish legal identity or any connection to state-sponsored activity. The operator's use of Chinese-language tools and infrastructure, combined with targeting of globally distributed systems, is consistent with patterns observed in both state-aligned and independent Chinese-speaking threat actors. No sanctions designations, government attributions, or intelligence community assessments have been publicly linked to the knaithe/KnYuan aliases as of this reporting. The operational security failures—exposing session logs, API keys, and target lists via an unintended HTTP server—suggest a lower level of tradecraft discipline than typically associated with advanced persistent threat groups backed by nation-state resources.
Business Impacty pro region
The campaign's global targeting scope—encompassing over 460 systems across multiple countries, with particular focus on the 25,000+ n8n instances identified in China—underscores the borderless nature of AI-enabled cyber operations. European organizations operating Langflow, n8n, Marimo, or NetScaler appliances face exposure if systems remain unpatched or publicly accessible without authentication. The use of FOFA, a Chinese search engine for internet-connected devices, for target enumeration reflects tooling preferences common among Chinese-speaking actors but accessible to any adversary. The campaign's reliance on publicly available exploits and open-source frameworks suggests that similar techniques will proliferate rapidly across threat actor ecosystems, regardless of geographic origin. For NATO allies and EU member states, the operational model presents a force-multiplication challenge: adversaries can now sustain reconnaissance and exploitation campaigns at scale with reduced human capital, complicating attribution and increasing the volume of malicious traffic that defenders must triage. The exposure of workflow automation platforms—often used in enterprise DevOps and data science environments—creates potential footholds into sensitive research, development, and operational technology networks across critical infrastructure sectors.
Forecast
If AI-assisted exploitation frameworks continue to mature and proliferate, defenders should anticipate a sustained increase in the volume and velocity of opportunistic scanning and exploitation attempts targeting newly disclosed vulnerabilities. Organizations that delay patching of internet-facing workflow, notebook, and identity provider systems—particularly Langflow, n8n, Marimo, and NetScaler appliances—are likely to face elevated risk as autonomous agents systematically enumerate and probe exposed assets. If additional threat actors adopt similar toolchains, the operational tempo of low-to-moderate sophistication campaigns may outpace traditional threat intelligence cycles, requiring greater reliance on automated patch management and zero-trust architectures that assume breach. Should state-aligned groups integrate these techniques into advanced persistent threat operations, the combination of AI-driven reconnaissance with human-directed post-exploitation could compress intrusion timelines and complicate incident response. Regulatory and policy responses are likely to emerge within 12–18 months if AI-enabled cyber operations result in significant disruptions to critical infrastructure or data breaches affecting EU or US entities, potentially including export controls on frontier AI models or frameworks designed for offensive use.
