INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

AI-Driven Hackers Automate Cyberattacks Using DeepSeek Models

| 2026-08-03 15:52 CRITICAL HIGH
Executive Summary AI-generated
The Chinese actor behind the recent cyberattacks using AI-driven tools, DeepSeek, has been identified as Unit 42. This autonomous scanning and exploitation campaign targeted Citrix NetScaler vulnerabilities across multiple organizations worldwide, including Malaysia, China, and others. The attacks leveraged a customized Hermes Agent with advanced red-teaming skills to identify and exploit weaknesses in various software systems. A Langflow vulnerability was also exploited, leading to the discovery of 84 live instances that were vulnerable to exploitation. This campaign highlights the sophistication and adaptability of modern cyber threats, as well as the importance of robust security measures to detect and respond to such attacks.
Technical Mitigations AI-generated
* Implement a secure file system and configure it to use isolated staging folders for sensitive data, such as API keys and exploit scripts. * Regularly update and patch large language models (LLMs) like Qwen, GLM, Kimi, MiniMax, and Codex to prevent exploitation of known vulnerabilities. * Use proxy servers or VPNs to route traffic through a third-party proxy when using Western tools like Claude Code and Codex, which may be vulnerable to attack. * Configure Hermes Agent with custom red-teaming skills that prioritize trusted tools over unknown ones, such as fofa-cyberspace-search: a custom procedure template instructing DeepSeek to use the actor's fofoapi.py script for internet asset enumeration.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Hermes AgentOperation Hermes Agent CVE-2026-33017CVE-2026-33017 CVE-2026-33824CVE-2026-33824 CVE-2026-34486CVE-2026-34486 CVE-2026-21858CVE-2026-21858 CVE-2026-39987CVE-2026-39987 CVE-2026-0300CVE-2026-0300 CVE-2026-3055CVE-2026-3055 CVE-2025-68613CVE-2025-68613
Target & Sectors
NORTH_AMERICA NORTH_AMERICA APAC APAC MIDDLE_EAST MIDDLE_EAST EUROPE EUROPE governmentgovernment defensedefense
Incident Timeline
‎May 5, 2026
Threat actors used AI to automate cyberattacks using DeepSeek.
‎May 7, 2026
Chinese actor DeepSeek customized Hermes Agent with a red-teaming framework, integrating it to automate cyberattacks through Hermes Agent's LLM jailbreaking and fofoapi.py script-based web-terminal exploitation.
observable fofoapi.py
organisation WebSocket
organisation MCP
organisation Nuclei
‎2026/08/03
The Chinese actor used AI to automate cyberattacks on 100 systems, targeting a Malaysian government entity.
infrastructure N8N
organisation FOFA
victims 647,017 target
victims 25,209 target
organisation Target Enumeration and Exploitation Attempts
victims 50 remaining Chinese targets
organisation GitHub
organisation IP
infrastructure 100 IP addresses
organisation Vulnerability Assessment
infrastructure 1.121.0
infrastructure 1.120.4
organisation Citrix NetScaler ADC & Gateway
organisation Manual Active
organisation Apache Tomcat
organisation PAN
organisation User-ID Authentication Portal
financial 9.9 Automation Exploitation attempt
organisation Cortex Xpanse
organisation Langlow
organisation Citrix ADC/Netscaler
organisation GLM
organisation Telegram
organisation Citrix NetScaler
infrastructure 11 Marimo notebook endpoints
organisation Frontier AI Defense
organisation the Citrix NetScaler
organisation Command
organisation WebSocket
organisation PoC
data_breach 10 file langflow_targets.txt
infrastructure Windows
organisation NetScaler
organisation Windows IKE
organisation Windows IKE Extensions
organisation API
organisation SecurityAffairs
infrastructure 18.0
infrastructure 117.3
infrastructure 108.2
organisation IKE
organisation the Operation Hermes
infrastructure 8888 http.server
organisation PAN-OS CVE-2026-0300
organisation User-ID Authentication Portal (Captive Portal
organisation Chinese-Speaking Threat Actor Harnesses AI Models
organisation Technical Analysis
organisation DeepSeek/Hermes
organisation Target Selection After
organisation Target
organisation Targeting Analysis and Limited Success
victims 460 targets
organisation Autonomous AI
organisation Palo Alto Networks Protection and Mitigation
organisation Cortex XDR
organisation XSIAM
organisation EPM
organisation Behavioral Threat Protection
organisation the Local Analysis
organisation Expander
organisation Cortex XSIAM/XDR/Cloud
organisation ASM
organisation Next-Generation Firewall
organisation Threat Prevention
organisation Palo Alto Networks
organisation Cyber Threat Alliance
organisation CTA
organisation Additional Resources
infrastructure 40 unique IP addresses
Tactical Metrics
Metrics
infrastructure
‎N8N
Affected Product
Metrics
infrastructure
11
Marimo Notebook Endpoints
Metrics
infrastructure
100
Ip Addresses
Metrics
infrastructure
‎Windows
Affected Product
Metrics
victims
647,017
Target
Metrics
victims
25,209
Target
Metrics
data_breach
10
File Langflow_Targets.Txt
Metrics
infrastructure
‎1.121.0
Software Version
Metrics
infrastructure
‎1.120.4
Software Version
Metrics
infrastructure
‎18.0
Software Version
Metrics
infrastructure
‎117.3
Software Version
Metrics
infrastructure
‎108.2
Software Version
Metrics
infrastructure
8,888
Http.Server
Metrics
financial
10
Automation Exploitation Attempt
Metrics
victims
50
Remaining Chinese Targets
Metrics
victims
460
Targets
Metrics
infrastructure
40
Unique Ip Addresses