Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
AI Summary
Unit 42 identified a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan who conducted an AI-enabled autonomous cyberattack campaign. The actor used the Hermes Agent framework with DeepSeek as the reasoning engine to autonomously enumerate vulnerabilities, acquire exploit code, and launch attacks without human intervention. They targeted multiple vulnerabilities including CVE-2026-33017 in Langflow and chained CVEs in n8n (CVE-2026-21858 and CVE-2025-68613), though exploitation attempts failed due to configuration requirements. Manual operations successfully exploited CVE-2026-3055 in Citrix NetScaler, leading to confirmed data exfiltration. The campaign was exposed when the actor accidentally exposed their infrastructure via an HTTP file server.
AI-extracted · verify before operational use
Extracted Entities 5 found
Indicators of Compromise 8 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | api[.]deepseek[.]com | Details → |
| Domain | code[.]newcli[.]com | Details → |
| Domain | dashscope[.]aliyuncs[.]com | Details → |
| GitHub Repo | qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC | Details → |
| GitHub Repo | Chocapikk/CVE-2026-21858 | Details → |
| GitHub Repo | oscar-mine/CVE-2026-33017 | Details → |
| Filename | fofoapi.py | Details → |
| Filename | langflow_poc.py | Details → |