hacker-news · Crawled Jul 31, 2026

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

3 IoCs 4 CVEs
Read original article ↗

AI Summary

A Chinese-speaking threat actor using the aliases knaithe and KnYuan leveraged the open-source Hermes Agent framework, powered by DeepSeek as the primary reasoning model, to autonomously conduct cyberattacks. The actor issued initial commands via Telegram, after which the agent independently identified internet-facing systems, selected public exploits, and attempted exploitation without further input. The campaign targeted vulnerabilities in Langflow, n8n, Marimo, and Citrix NetScaler systems, with confirmed exploitation of CVE-2026-3055 and CVE-2026-39987, though only three systems were successfully compromised. The operation was exposed due to an unintentional HTTP server exposing configuration files, API keys, exploit scripts, and logs.

AI-extracted · verify before operational use

Extracted Entities 4 found

Indicators of Compromise 3 extracted

Type Value Detail
Filename http.server Details →
Filename python3 -m http.server 8888 Details →
Filename /home/worker Details →

MITRE ATT&CK TTPs 42 techniques

T1021 Remote Services · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1046 Network Service Discovery · Discovery T1055 Process Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1059.004 Unix Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1203 Exploitation for Client Execution · Execution T1210 Exploitation of Remote Services · Lateral Movement T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1499 Endpoint Denial of Service · Impact T1505.003 Web Shell · Persistence T1552 Unsecured Credentials · Credential Access T1566 Phishing · Initial Access T1583 Acquire Infrastructure · Resource Development T1584 Compromise Infrastructure · Resource Development T1585 Establish Accounts · Resource Development T1586 Compromise Accounts · Resource Development T1587 Develop Capabilities · Resource Development T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1619 Cloud Storage Object Discovery · Discovery T1069 Permission Groups Discovery · Discovery T1087 Account Discovery · Discovery T1530 Data from Cloud Storage · Collection T1555 Credentials from Password Stores · Credential Access T1078.001 Default Accounts · Defense Evasion T1220 XSL Script Processing · Defense Evasion T1484 Domain or Tenant Policy Modification · Defense Evasion T1659 Content Injection · Initial Access