
A Chinese‑speaking threat actor using autonomous AI tools breached a Malaysian government agency and over 460 other targets in August 2026, according to Palo Alto Networks Unit 42. The intrusion, first detected on 3 August, exposed sensitive data and highlighted how machine‑learning models can drive attacks with little human oversight.
The attackers relied on a suite of models including DeepSeek, Hermes Agent, Qwen and GLM to scan for exposed services, select exploits and launch payloads automatically. They successfully exploited known weaknesses in Citrix NetScaler, Langflow and the workflow platform n8n, chaining together steps that would normally require manual analysis. No CVEs were directly tied to the campaign, but the actors reused public proof‑of‑concept code for those products.
Over the three‑day window from 3 to 5 August, the autonomous system attempted intrusions against more than 460 organisations, with three confirmed breaches including the Malaysian agency. Many attempts failed because the targeted systems were patched or protected by network segmentation, yet the speed at which the AI generated and tested exploit paths outpaced traditional detection.
Palo Alto’s Unit 42 traced the operator’s infrastructure to Zhuhai, China and linked the activity to the aliases knaithe and KnYuan. The campaign showed a preference for Chinese‑developed models, avoiding Western tools such as Claude Code due to concerns over anonymity and attribution. Despite the limited number of successes, the effort demonstrated a clear shift toward AI‑driven automation in offensive operations.
Defenders should prioritise patching Citrix NetScaler, Langflow and n8n to the latest versions released by their vendors, as the exploited flaws were publicly disclosed months before the campaign began. In addition, organisations must restrict administrative interfaces to internal networks only, enforce multi‑factor authentication for all remote access points and disable any unused services that could be leveraged as entry points. Enabling detailed audit logs on these systems and forwarding them to a central SIEM allows analysts to spot abnormal login spikes or unusual command