Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Summary
A Chinese-speaking threat actor, identified as knaithe and KnYuan, has reportedly used the open-source Hermes Agent framework with the DeepSeek AI model to launch autonomous cyberattacks. After receiving initial instructions via Telegram, the agent independently identified internet-facing systems and exploited vulnerabilities without further operator intervention.
IFF Assessment
The use of AI to autonomously identify and exploit vulnerabilities represents a significant advancement in automated attack capabilities, posing a greater threat to defenders.
Defender Context
This development highlights the emerging trend of AI-powered autonomous attacks, where threat actors can leverage AI to automate reconnaissance and exploitation phases. Defenders need to be prepared for faster, more sophisticated attacks that require advanced threat detection and automated response capabilities.