Palo Alto Networks’ Unit 42 says it found a Chinese-speaking operator who commanded a DeepSeek-based agent over Telegram; after that initial instruction, the agent scouted internet-facing systems and launched attacks on its own, with no further operator input recovered in the session.
Unit 42 tracks the operator under the aliases knaithe and KnYuan. The agent ran inside the open-source Hermes Agent framework, with DeepSeek as the primary reasoning model. It enumerated targets using FOFA, searched GitHub for trending proof-of-concept exploits, and prioritized vulnerabilities by severity and deployment scale before pivoting when initial attempts failed.
The campaign targeted more than 460 systems across seven exploit tracks spanning eight CVEs. Attempted chains hit Langflow (CVE-2026-33017), n8n (CVE-2026-21858 plus CVE-2025-68613) and Marimo (CVE-2026-39987), while manual operations used the NetScaler memory-overread flaw CVE-2026-3055. Unit 42 confirmed three successfully exploited targets overall.
The operation exposed itself when the agent started a file server in its home directory, leaking model configurations, API keys, exploit scripts, target lists and shell history. Unit 42 assesses the operator is based in Zhuhai, China, though public profiles do not establish legal identity or state ties.
Defenders should update internet-facing Langflow, n8n and Marimo deployments, plus customer-managed NetScaler appliances set up as SAML identity providers, and should cut public access to workflow and notebook interfaces wherever possible.
