Palo Alto Networks’ Unit 42 identified a Chinese-speaking threat actor, tracked as “knaithe”/”KnYuan” and assessed to be based in Zhuhai, who wired the DeepSeek model into the open-source Hermes Agent framework to autonomously enumerate targets, select vulnerabilities, source exploits, and attack more than 460 internet-facing systems after a single Telegram command. Unit 42 recovered a session in which the AI operated with no further human input, though the fully autonomous phase achieved only limited success due to target-side defenses. The actor’s related manual campaigns did confirm data exfiltration from Citrix NetScaler systems and command execution on exposed Marimo notebook instances, demonstrating a working end-to-end AI-driven offensive pipeline.