Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
A Chinese-speaking threat actor, operating under the aliases knaithe and KnYuan, is leveraging AI to conduct autonomous cyberattacks. Using the Hermes Agent framework and DeepSeek, they autonomously identified and exploited vulnerabilities, including a Citrix NetScaler vulnerability and n8n instances, while also conducting manual exploitation techniques. The actor’s operational security practices, such as disabling conversation logging and deleting exploit directories, were notable, but an unintentional exposure of their workspace – including AI tool configurations, API keys, and exploit scripts – provided valuable insight into their methodology. The actor’s activity demonstrates a sophisticated and evolving approach to vulnerability exploitation, combining automated scanning with targeted manual operations.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
