Chinese Operator Turns DeepSeek Into a Self-Driving Hacker via Telegram

Unit 42 says an attacker gave one Telegram command and let an AI agent pick the targets, choose the exploits, and run the intrusion on its own.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial 16:9 photograph of a close-up view of a glowing computer screen displaying abstract flowing green and amber data streams, with a physic
Share

Key points

  • Palo Alto Networks' Unit 42 says a Chinese-speaking operator used the DeepSeek AI model inside an open-source framework called Hermes Agent to run an intrusion with almost no human input.
  • The attacker sent a single instruction over Telegram, the messaging app, and the agent then hunted for internet-exposed systems and picked public exploits on its own.
  • Researchers recovered no further operator commands in the session they observed.
  • The operator is tracked under the aliases knaithe and KnYuan.
  • The case is one of the clearest public examples so far of an AI agent driving an offensive operation end to end.

A Chinese-speaking attacker pointed an AI chatbot at the internet and told it to go hacking. That, in short, is what Palo Alto Networks' Unit 42 threat intelligence team says it watched happen.

The researchers describe an operator, tracked as knaithe and KnYuan, using the DeepSeek large language model through an open-source project called Hermes Agent. A large language model is the kind of AI that powers chatbots like ChatGPT. An "agent" framework wraps that chatbot in code so it can take actions on a computer, not just answer questions.

The operator gave the agent one instruction over Telegram. After that, according to Unit 42, the AI did the rest.

What actually happened?

The agent scanned for internet-facing systems, meaning servers reachable from the open web, then picked publicly known exploits to try against them. Unit 42 says it found no further messages from the human operator during the session it recovered. The intrusion attempt ran on autopilot.

This matters because offensive hacking usually involves a lot of hands-on work: choosing targets, testing which flaw fits which server, adjusting when something breaks. Handing that decision-making to an AI agent compresses the job into a single prompt.

The story was first reported by The Hacker News, drawing on Unit 42's research.

Who is behind it?

Attribution here is narrow and careful. Unit 42 links the activity to a Chinese-speaking operator using the handles knaithe and KnYuan. The report stops short of tying the person to a known Chinese state cluster such as Mustang Panda or APT41, and no vendor has publicly done so at the time of writing. Treat this as an individual actor experimenting with AI tooling, at low to medium confidence, until more overlaps emerge.

Capability is not the same as intent. An agent that can pick exploits off a list is not the same as one running bespoke zero-days, meaning software flaws the maker doesn't know about yet. What Unit 42 describes is automation of the noisy, opportunistic end of the intrusion market, not a step change in tradecraft.

Why does this matter for ordinary people?

It lowers the bar. A single operator, with one Telegram message, can now aim a tireless scanner-and-exploiter at the whole internet. For anyone running a small business website, a home server, or an unpatched office system, the practical answer is unchanged but more urgent: keep software updated, and do not leave admin panels exposed to the web.

At a glance

Detail What Unit 42 reports
AI model used DeepSeek
Agent framework Hermes Agent (open-source)
Control channel Telegram
Operator aliases knaithe, KnYuan
Human input observed A single initial instruction
Exploits used Publicly available, against internet-facing systems

What to watch next

Two questions sit on top of this report. First, whether other vendors see the same aliases or the same Hermes Agent traffic and can add overlapping infrastructure to the picture. Second, whether the operator graduates from public exploits to anything custom. Until then, this is a proof of concept caught in the wild, not a fully formed campaign.

© 2026 Threat Vectr