unit42 · Crawled Jul 30, 2026

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

8 IoCs 5 CVEs
Read original article ↗

AI Summary

Unit 42 identified a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan who conducted an AI-enabled autonomous cyberattack campaign. The actor used the Hermes Agent framework with DeepSeek as the reasoning engine to autonomously enumerate vulnerabilities, acquire exploit code, and launch attacks without human intervention. They targeted multiple vulnerabilities including CVE-2026-33017 in Langflow and chained CVEs in n8n (CVE-2026-21858 and CVE-2025-68613), though exploitation attempts failed due to configuration requirements. Manual operations successfully exploited CVE-2026-3055 in Citrix NetScaler, leading to confirmed data exfiltration. The campaign was exposed when the actor accidentally exposed their infrastructure via an HTTP file server.

AI-extracted · verify before operational use

Extracted Entities 5 found

Indicators of Compromise 8 extracted

Type Value Detail
Domain api[.]deepseek[.]com Details →
Domain code[.]newcli[.]com Details →
Domain dashscope[.]aliyuncs[.]com Details →
GitHub Repo qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC Details →
GitHub Repo Chocapikk/CVE-2026-21858 Details →
GitHub Repo oscar-mine/CVE-2026-33017 Details →
Filename fofoapi.py Details →
Filename langflow_poc.py Details →

MITRE ATT&CK TTPs 42 techniques

T1021 Remote Services · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1046 Network Service Discovery · Discovery T1055 Process Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1059.004 Unix Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1203 Exploitation for Client Execution · Execution T1210 Exploitation of Remote Services · Lateral Movement T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1499 Endpoint Denial of Service · Impact T1505.003 Web Shell · Persistence T1552 Unsecured Credentials · Credential Access T1566 Phishing · Initial Access T1583 Acquire Infrastructure · Resource Development T1584 Compromise Infrastructure · Resource Development T1585 Establish Accounts · Resource Development T1586 Compromise Accounts · Resource Development T1587 Develop Capabilities · Resource Development T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1619 Cloud Storage Object Discovery · Discovery T1069 Permission Groups Discovery · Discovery T1087 Account Discovery · Discovery T1530 Data from Cloud Storage · Collection T1555 Credentials from Password Stores · Credential Access T1484 Domain or Tenant Policy Modification · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1220 XSL Script Processing · Defense Evasion T1659 Content Injection · Initial Access