August 1, 20265 min read

DeepSeek AI Powers Autonomous Cyberattacks on Vulnerable Servers

A hacker employs DeepSeek AI and Hermes Agent for autonomous attacks on exposed servers, showcasing alarming advancements in cybercriminal capabilities. This article explores the implications of AI-driven cybersecurity threats and the necessity for robust defenses.

Cybersecurity analysis of AI cyberattacks

A recent analysis by Palo Alto Networks' Unit 42 has unveiled a concerning trend in the realm of cybersecurity: a Chinese-speaking hacker is utilizing the DeepSeek AI model alongside the open-source Hermes Agent to conduct automated cyberattacks on vulnerable servers with minimal human involvement.

The findings reveal that the hacker, operating under the aliases "knaithe" and "KnYuan," refers to themselves as a "binary security researcher." This autonomous attack method illustrates a disturbing advancement in cybercriminal capabilities, pushing the boundaries of how artificial intelligence can be leveraged for offensive purposes.

Discovery of Autonomous Attacks

The investigation into these cyberattacks began when researchers from Palo Alto Networks stumbled upon the threat actor's environment, inadvertently exposed due to the Hermes Agent creating a web server from its own home directory. This exposure disclosed vital information including API keys, exploit scripts, target lists, shell history, and logs detailing the AI's attack strategies. Although the attacks did not result in successful server compromises, the incident provided critical insights into an end-to-end offensive AI workflow capable of exploring, evaluating, and attempting to exploit vulnerabilities.

Key Components: DeepSeek and Hermes Agent

DeepSeek serves as the reasoning engine foundational to the operations of Hermes Agent, an advanced open-source framework designed for interaction with operating system terminals, executing commands, and connecting to the internet. One notable feature of the agent is its "Yolo" mode. This mode enables Hermes to autonomously execute commands, including potentially hazardous ones, without seeking prior approval from its operator. Thus, the threat actor can orchestrate complex attacks with ease.

Operational Insights from May 2026

In one instance from May 2026, researchers recovered a session showcasing the capabilities of DeepSeek and Hermes. The operator provided an initial command, after which the agent autonomously conducted all subsequent operations without requiring further human input. The first targets included Langflow servers exposed to the internet, vulnerable to the specific cybersecurity vulnerability identified as CVE-2026-33017. Utilizing the FOFA internet asset search engine, the agent identified 84 exposed instances and proceeded to scan them for vulnerabilities.

Search for Additional Vulnerabilities

Upon finding that the initial targets were not exploitable, the agent exhibited advanced behavior by searching for additional vulnerabilities and potential targets. The agent extensively analyzed public exploit repositories before zeroing in on the n8n workflow automation platform, which had over 647,000 exposed instances logged through FOFA. Following this, Hermes downloaded exploit code tailored to exploit two vulnerabilities: CVE-2026-21858 and CVE-2025-68613. However, the agent encountered a setback as it discovered that the attempts to access unauthenticated file upload forms were thwarted due to required authentication.

Efficiency of Autonomous Processes

Despite the failures to compromise any targets, Unit 42 emphasized the importance of this campaign as a crucial demonstration of the efficiency with which AI can operate. This autonomous process, marked by rapid identification of targets and narrowing of focus, is particularly alarming as it condenses hours of manual analysis into mere minutes. According to Palo Alto Networks, this capability highlights a significant shift in the speed and scope of cyberattacks, as the AI managed its own computational resources while deftly navigating attack strategies.

Manual Attack Activities

While the AI agent was pivotal in attacking automated vulnerabilities, the threat actor also engaged in manual attacks. These efforts targeted over 460 systems through various vulnerabilities affecting products such as Citrix NetScaler, Apache Tomcat, Marimo Notebook, and Windows IKE VPN. Notably, three successful compromises were attributed to the Citrix NetScaler vulnerability, referred to as CVE-2026-3055, with the attacker leveraging it to extract memory and seek out authentication cookies which could authorize session hijacking.

Cybersecurity professionals reviewing attack logs

Previous Incidents and Hermes AI Usage

This recent incident is not the first time Hermes AI has appeared in the spotlight. An earlier disclosure related to the Thailand Ministry of Finance revealed similar shortcomings in cybersecurity measures, exposing vital information concerning a troubling cyberattack. This incident came to light when security researcher Bob Diachenko, alongside Hunt.io, discovered unprotected web directories filled with exploit tools, web shells, credentials, compiled payloads, and activity logs from Hermes.

In that scenario, Hermes was observed executing automation routines in unattended "YOLO" mode; however, it lacked the capacity to autonomously select targets or determine the method of compromise. A human operator was responsible for providing the primary target and tools while Hermes handled the routine tasks post-access. This stark contrast with the current autonomous attacks highlights the rapid evolution of AI's role in cyber offenses.

Security Norms Under Threat

The emergence of autonomous AI-driven attacks marks a significant turning point in cybersecurity. Cybersecurity practices that relied heavily on conventional human oversight are increasingly rendered obsolete as autonomous systems like Hermes take the reins. The implications are far-reaching, prompting organizations to reassess their defenses against increasingly sophisticated threats.

Key Takeaways

  • The rise of AI-driven attacks marks a new chapter in cybersecurity challenges.
  • DeepSeek AI enables autonomous operations of the Hermes Agent framework.
  • Research shows AI could condense hours of analysis into minutes.
  • Manual attacks are still prevalent, highlighting a mixed approach to cyber offense.
  • The recent attack underscores the need for robust cybersecurity measures against evolving threats.

Conclusion

The use of DeepSeek AI within autonomous cyberattacks, combined with the functionalities offered by Hermes Agent, represents an alarming advancement in the techniques employed by cybercriminals. As these technologies become more sophisticated, organizations must reevaluate and strengthen their cybersecurity protocols to mitigate the risks associated with AI-driven attacks. This evolving landscape of cyber threats necessitates a proactive and dynamic approach to maintaining security in both public and private sectors.

Frequently Asked Questions

DeepSeek AI is an advanced model used by cybercriminals to autonomously identify and exploit vulnerabilities in servers.
#Cybersecurity#DeepSeek AI#Hermes Agent#AI Threats#Autonomous Attacks