Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact. The actor, operating under the aliases knaithe and KnYuan, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator. They orchestrated this operator via Telegram for the following activities:

  1. Independently enumerating targets and their vulnerabilities using FOFA
  2. Sourcing exploit tools
  3. Initiating attacks without human intervention

In parallel with their use of DeepSeek as their autonomous operator platform, the actor configured multiple large language models (LLMs) (Qwen, GLM, Kimi, MiniMax). We also identified limited usage and testing of Western platforms. This includes Claude Code for connectivity testing and proxy validation. There were also signs of usage of Codex on exploit development directories. This limited usage is consistent with evaluating the AI-market to identify their preferred tool set.

Full report : Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks.