started · updated
DeepSeek AI used to automate cyberattacks against 460 targets
Researchers from Unit 42, the threat intelligence division of Palo Alto Networks, have identified a cyberattack campaign where a Chinese-speaking threat actor used the DeepSeek AI model to automate system exploitation.
By integrating DeepSeek with the open-source Hermes Agent framework, the attacker was able to conduct reconnaissance, select exploits, and change strategies autonomously after receiving a single instruction via Telegram. The Hermes Agent framework allows AI models to access terminals and execute tasks without continuous human supervision.
The campaign targeted over 460 internet-exposed systems, combining autonomous AI-driven operations with manual procedures. While DeepSeek served as the primary reasoning engine, researchers also noted limited use of other models, including Claude Code and Qwen Code.
Entities
DeepSeek · Hermes Agent · Palo Alto Networks · Unit 42 · Xinhua