Unit 42 Report: Hackers Harness DeepSeek and Other LLMs for Autonomous Cyberattacks
cyb3rops · x · 2026-08-01
Palo Alto Networks' Unit 42 threat research team published a report detailing an AI-enabled autonomous hacking campaign by a Chinese-speaking threat actor.
- Tactics: The adversary leveraged the Hermes Agent framework with DeepSeek as an autonomous offensive operator. Orchestrated via Telegram, the AI independently enumerated targets using FOFA, sourced exploit tools, and initiated attacks.
- LLM Abuse: Alongside DeepSeek, the actor configured multiple Chinese LLMs (Qwen, GLM, Kimi, MiniMax). Limited testing of Western tools like Claude Code and Codex was also noted for proxy validation and exploit development.
- Impact: Targeting seven distinct vulnerabilities, the campaign combined AI-driven enumeration with manual exploitation, achieving confirmed impact on infrastructure.
More from coding & agent
- Astounding AI Coding Efficiency: Feature Shipped in Under 2 Hours — charliedeets · 2026-08-01
- Practicing Long-Running Async AI Workflows: Automating Sales and Conversion — edgarpavlovsky · 2026-08-01
- SkillsGate: Open-Source Visual Skill Manager for 20+ AI Agents — tom_doerr · 2026-08-01
- Sleepwalker: Export Web Pages to AI-Readable OKF Markdown — spicemelange13 · 2026-08-01
- Testing Apple Xcode 27 Coding Agent: Ships to TestFlight but Fails Complex Game State — atShruti · 2026-08-01
- Made in Canada: Developer Shares E-commerce Search Stack Ditching OpenAI Entirely — Nils_Reimers · 2026-08-01