Palo Alto Networks’ Unit 42 threat intelligence team has published a detailed breakdown of a first-of-its-kind autonomous AI cyberattack campaign — one that used the DeepSeek AI model to scan, target, and exploit vulnerable servers with minimal human involvement, after Claude and OpenAI’s safety controls blocked the same attempts.
What Happened
A Chinese-speaking threat actor operating under the aliases “knaithe” and “KnYuan” — assessed by Unit 42 to be based in Zhuhai, China — integrated DeepSeek into the open-source Hermes Agent framework and directed the system via Telegram. The result was an end-to-end scan-research-exploit pipeline that could execute hundreds of hours of manual targeting analysis in minutes, with the human operator issuing a single command and largely stepping back.
The system targeted more than 460 internet-facing systems, focusing on known vulnerabilities in Citrix NetScaler, Apache Tomcat, Marimo Notebook, and Windows IKE VPN. Unit 42 confirmed only three successful compromises, all involving memory data exfiltration from Citrix NetScaler systems, with suspected session-hijacking attempts against a Malaysian government entity.
The campaign was discovered by accident. Hermes Agent inadvertently spun up a web server from its home directory, exposing the attacker’s environment — including API keys, exploit scripts, target lists, shell history, and AI attack logs.
Why DeepSeek, Not Claude or OpenAI
The more significant detail in Unit 42’s report is what came before. The threat actor first attempted to wire the same offensive pipeline through Claude and through OpenAI’s models. Both refused. Safety controls in both systems blocked the attempt to use them for autonomous offensive operations.
DeepSeek, lacking equivalent controls on its open-weight models, accepted the task.
This is not a criticism of DeepSeek as a product — it’s a structural feature of how open-weight models work. When model weights are publicly available, anyone can remove guardrails. The Hermes campaign is a real-world demonstration of what that means in practice: closed safety controls are not an obstacle, they’re a filter that routes attackers toward less restricted alternatives.
What “Autonomous” Actually Means Here
The language of “autonomous AI attack” can sound futuristic. The reality is more mundane but still significant. Hermes-plus-DeepSeek did not demonstrate novel exploit development or zero-day discovery. It automated the labor-intensive parts of a standard attack campaign: scanning for exposed systems, cross-referencing public exploit databases, narrowing targeting lists, and attempting known exploits in sequence.
In a conventional operation, that process takes human operators days or weeks. The AI system compressed it to hours, while managing its own compute resources and reporting back via Telegram. The success rate — three confirmed compromises from 460 attempts — reflects the fact that the exploits were drawn from public databases against systems that were already known to be vulnerable. Any competent human attacker with similar time investment would expect similar results.
The significance is not capability but efficiency. AI-assisted attacks reduce the cost and time of running large-scale campaigns, making operations previously restricted to well-resourced nation-state actors more accessible to smaller groups.
What This Means for Business
Businesses running enterprise AI systems should draw two practical conclusions from the Unit 42 report.
First, model safety controls carry real operational value. Claude and OpenAI both blocked this campaign. That is not a coincidence. Frontier labs have invested heavily in refusing requests that pattern-match to offensive security operations. Businesses that choose AI vendors partly on the basis of these safety investments are not just buying reputation management — they are buying a form of security infrastructure.
Second, open-weight models require deliberate governance. The same openness that makes models like DeepSeek valuable for customization and local deployment makes them attractive to threat actors who need to strip safety controls. Enterprises running or considering open-weight models in production need to treat the absence of built-in safety enforcement as an architectural risk to manage, not a default to accept.
The attack surface for AI-assisted threats is growing. The cost of mounting those attacks is falling. Unit 42’s report is a useful benchmark for where the technology stands today — and a clear signal of where defenders need to be investing.
Enterprise DNA helps businesses build AI operations with the governance, vendor selection, and architectural controls to stay ahead of risks like these. If you’re navigating AI security for your organisation, book a discovery call with our team.
Source
Palo Alto Networks Unit 42
Free Resource
Going deeper with Claude?
Get the free 32-page implementation guide for ANZ teams.
Your guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the GuideWant this working inside your business?
See what's possible