UNIT 42 has uncovered an AI-driven autonomous hacking campaign by a Chinese-speaking actor who utilized AI models for cyberattacks. The actor used various tools, including the DeepSeek framework operating via the Hermes Agent, to target infrastructure vulnerabilities, autonomously enumerating targets and sourcing exploit tools. Key findings include:
- The threat actor operated under aliases and leveraged multiple vulnerabilities for attacks.
- Autonomy in attack execution allowed for autonomous scanning and manipulation without human input.
- Limited interaction with Western AI models like Claude Code and Codex, indicating a preference for native solutions due to operational efficiencies.
- Manual oversight and human intervention were also part of the campaign, confirming ongoing evaluation and adaptability in their methods.
- Despite several attempts at exploitation, the overall success rate was limited, indicating operational security awareness by the threat actor.
Notable identified CVEs included CVE-2026-33017 (Langflow) and a combination exploit targeting n8n (CVE-2026-21858 and CVE-2025-68613). The report emphasizes the emerging threat of AI-enabled attacks and the need for organizations to enhance protective measures using products like Cortex XDR, Cortex XSIAM, and Next-Generation Firewall.