Technology News

DeepSeek Agent Executes Autonomous Attacks After Telegram Cue

A Chinese‑speaking threat actor commandeered DeepSeek through the Hermes Agent framework to launch attacks without further input after a Telegram instruction, prompting Palo Alto Networks’ Unit 42 to trace the operator through aliases knaithe and KnYuan.

A recent investigation by Palo Alto Networks’ Unit 42 revealed a Chinese‑speaking threat actor leveraging the open‑source DeepSeek tool via the Hermes Agent framework to conduct attacks autonomously.

DeepSeek, a data‑collection engine, was instructed through a Telegram message, after which the Hermes Agent framework carried out the operation with no further operator guidance.

Unit 42 researchers noted that the agent scoured the internet for publicly exposed systems and automatically selected applicable exploits from the catalog of known vulnerabilities.

The autonomous behavior extended to choosing the most effective public exploits, allowing the attacker to bypass manual decision points.

During the engagement, no additional operator input was recovered, indicating the attacker had fully delegated execution to the agent.

Unit 42 was able to track the operator through the aliases knaithe and KnYuan, providing a clear link to the threat actor’s identity.

These findings underscore the growing sophistication of threat actors who combine readily available tools with minimal human intervention.

Security teams are advised to monitor for signs of autonomous agent activity, especially when open‑source tools are involved.

DeepSeek Agent Executes Autonomous Attacks After Telegram Cue

A recent investigation by Palo Alto Networks’ Unit 42 revealed a Chinese…

A recent investigation by Palo Alto Networks’ Unit 42 revealed a Chinese…

A recent investigation by Palo Alto Networks’ Unit 42 revealed a Chinese‑speaking threat actor leveraging the open‑source DeepSeek tool via the Hermes Agent framework to conduct attacks autonomously.

DeepSeek, a data‑collection engine, was instructed through a Telegram message, after which the Hermes Agent framework carried out the operation with no further operator guidance.

Unit 42 researchers noted that the agent scoured the internet for public…

Unit 42 researchers noted that the agent scoured the internet for public…

Unit 42 researchers noted that the agent scoured the internet for publicly exposed systems and automatically selected applicable exploits from the catalog of known vulnerabilities.

The autonomous behavior extended to choosing the most effective public exploits, allowing the attacker to bypass manual decision points.

During the engagement, no additional operator input was recovered, indic…

During the engagement, no additional operator input was recovered, indic…

During the engagement, no additional operator input was recovered, indicating the attacker had fully delegated execution to the agent.

Unit 42 was able to track the operator through the aliases knaithe and KnYuan, providing a clear link to the threat actor’s identity.

These findings underscore the growing sophistication of threat actors wh…

These findings underscore the growing sophistication of threat actors wh…

These findings underscore the growing sophistication of threat actors who combine readily available tools with minimal human intervention.

Security teams are advised to monitor for signs of autonomous agent activity, especially when open‑source tools are involved.