Chinese Hacker Leverages Telegram to Command DeepSeek for Autonomous Cyber Attacks

0
56

Key Takeaways

  • A Chinese‑speaking threat actor (aliases knaithe and KnYuan) used the open‑source Hermes Agent framework, powered primarily by the DeepSeek reasoning model, to launch largely autonomous attacks after a single Telegram instruction.
  • The actor attempted to exploit more than 460 internet‑facing systems across seven exploit tracks that involved eight CVE identifiers, including a two‑vulnerability chain in the n8n workflow platform.
  • Automated attempts against Langflow and n8n failed because the exposed instances did not meet the required configuration (or only partially met) the prerequisites for the exploits (e.g., missing auto_login, required authentication).
  • In separate manual operations the actor exfiltrated data via the NetScaler memory‑overread flaw CVE‑2026‑3055 and achieved command execution on Marimo instances through CVE‑2026‑39987, although Unit 42 later confirmed only three successful compromises overall, creating an inconsistency in the report.
  • The Hermes Agent inadvertently exposed the actor’s toolkit by starting an exposed Python HTTP server (python3 -m http.server 8888), leaking model configs, API keys, exploit scripts, target lists, and logs.
  • Defenders should patch exposed Langflow, n8n, and Marimo systems, secure NetScaler ADC/Gateway appliances used as SAML identity providers, and remove unnecessary public access to workflow and notebook interfaces.
  • Attribution points to an operator based in Zhuhai, China, supported by a GitHub profile and an older blog under the same handle, though no legal or state‑level connection was established.

Background and Attribution
Palo Alto Networks’ Unit 42 released a detailed analysis of a campaign in which a Chinese‑speaking threat actor, tracked under the aliases knaithe and KnYuan, leveraged the open‑source Hermes Agent framework to conduct attacks. The operator’s activity was first observed via a Telegram message that instructed the agent to begin its work; after that initial cue, no further human input was detected in the session logs. The aliases appear on a GitHub profile displaying the name “KnYuan Knaithe” and on an older blog where the author describes themselves as a binary security researcher residing in Zhuhai, China. While this public material aligns with Unit 42’s geographic assessment, it does not independently verify the operator’s legal identity or any affiliation with a state entity.

Hermes Agent Framework and Autonomous Workflow
The Hermes Agent framework provides a modular environment where a reasoning model can invoke terminal commands, reuse pre‑built skill modules, and schedule unattended tasks. In this operation, the primary reasoning model was DeepSeek, which supplied the agent with the ability to interpret instructions, select exploits, and execute them without continual operator guidance. Unit 42 also noted limited usage of Claude Code and Qwen Code within the agent’s environment, and discovered traces of Codex in exploit‑development directories, although chat logs that would confirm actual Codex use were not preserved. The framework’s documentation confirms that it can be triggered via Telegram, run arbitrary commands, and maintain persistent, scheduled jobs—capabilities that the actor exploited to launch a largely self‑sufficient attack chain.

Scope of Targeting and Exploit Tracks
According to the report, the actor attempted to compromise more than 460 internet‑facing targets. These attempts were organized into seven distinct exploit tracks, which collectively involved eight Common Vulnerabilities and Exposures (CVE) identifiers. The n8n track is noteworthy because it chains two vulnerabilities—CVE‑2026‑21858 (unauthenticated file access) and CVE‑2025‑68613 (expression injection)—into a single attack path, thereby counting as two CVEs within one track. The other tracks targeted Langflow, Marimo, NetScaler, and additional services. The breadth of the targeting illustrates the actor’s strategy of casting a wide net while relying on the agent’s autonomous decision‑making to prioritize which vulnerabilities to pursue based on factors such as severity, deployment scale, and apparent exploitability.

Outcome of Automated Exploits Against Langflow and n8n
The DeepSeek‑driven automation first went after a Langflow code‑injection flaw tracked as CVE‑2026‑33017. After downloading a public exploit, the agent used the FOFA search engine to enumerate 84 Langflow instances and identified one running version 1.3.4. However, the attack stalled because the target lacked the required auto_login setting and did not expose a usable public flow identifier, preventing the exploit from succeeding.

Next, the agent shifted to the n8n workflow automation platform. It assembled a chain combining CVE‑2026‑21858 and CVE‑2025‑68613. FOFA returned a staggering 25,209 n8n systems located in China during the session. The agent sampled roughly 100 of these, probed about 40, and found three instances running vulnerable versions. One of those exposed three form endpoints, but each required authentication; moreover, more than 50 additional targets lacked a usable public form, resulting in zero successful n8n compromises. Both Langflow and n8n have since issued patches: Langflow fixed CVE‑2026‑33017 in version 1.9.0, while n8n addressed CVE‑2026‑21858 in version 1.121.0 and CVE‑2025‑68613 in versions 1.120.4, 1.121.1, and 1.122.0, making 1.121.1 the earliest release that mitigates both chained flaws.

Manual Operations and Data Exfiltration
Beyond the automated attempts, Unit 42 documented manual actions carried out by the same operator. Using the NetScaler memory‑overread vulnerability CVE‑2026‑3055, the actor exfiltrated data from three organizations that had exposed NetScaler ADC or Gateway appliances configured as SAML identity providers. Separately, the attacker achieved command execution on 11 Marimo instances via CVE‑2026‑39987. Despite these claims, the report later states that Unit 42 could confirm only three successfully exploited targets across the entire operation, a figure that does not reconcile with the earlier counts of three NetScaler breaches and eleven Marimo compromises. The discrepancy remains unresolved, and The Hacker News has sought clarification from Palo Alto Networks.

Decision‑Making Process of the Agent
The Hermes Agent exhibited a methodical approach to exploit selection. After gaining an initial foothold, it routinely checked the versions of exposed services, downloaded corresponding public exploits, and abandoned paths that appeared unproductive. When a chosen exploit failed due to configuration mismatches (e.g., missing authentication tokens or required flags), the agent would reassess the target pool, prioritize vulnerabilities based on a combination of severity scores, the number of exposed instances, and the likelihood of successful exploitation, then pivot to an alternative CVE. This iterative, severity‑driven looping enabled the agent to cover a broad attack surface while minimizing wasted effort on low‑yield targets.

Recommendations for Defenders
Unit 42 advises organizations to take several concrete steps to mitigate similar threats. First, patch any exposed Langflow, n8n, and Marimo installations to the versions noted above. Second, for NetScaler ADC/Gateway appliances that serve as SAML identity providers, administrators should verify the presence of the line add authentication samlIdPProfile .* in the configuration and apply the fixed builds listed in Citrix’s security bulletin for CVE‑2026‑3055. Third, reduce the attack surface by removing unnecessary public access to workflow automation interfaces, notebook servers, and any other administrative portals that are not required for legitimate business functions. Finally, monitor for anomalous processes such as an unexpected python3 -m http.server binding, which could indicate a compromised agent attempting to leak its internal toolkit.

Accidental Exposure via Hermes Agent
A critical operational misstep exposed the actor’s entire toolkit. The Hermes Agent, while executing its tasks, inadvertently launched a Python simple HTTP server with the command python3 -m http.server 8888 from the /home/worker directory. This server made publicly accessible a trove of sensitive files, including the DeepSeek model configurations, API keys, exploit scripts, target lists, shell histories, and logs of the autonomous session. The leak likely facilitated Unit 42’s analysis and underscores the danger of allowing agents to bind to uncontrolled network interfaces without proper segmentation or authentication controls.

Model Usage and Supporting Tools
DeepSeek served as the primary reasoning engine within the Hermes Agent, providing the logical framework for task planning, exploit selection, and command execution. Unit 42 observed only sporadic use of Claude Code and Qwen Code, suggesting they may have been employed for auxiliary scripting or testing but did not play a central role. Traces of Codex were found in directories associated with exploit development, indicating the actor might have experimented with this model for generating or refining payloads; however, the absence of preserved chat logs prevents definitive confirmation of its actual utilization in the campaign.

Detailed Walk‑through of the May 2026 Session
The report includes a granular timeline from a recovered May 2026 session. After the initial Telegram prompt, DeepSeek fetched a public exploit for CVE‑2026‑33017 (Langflow), queried FOFA for Langflow instances, and identified a single host running version 1.3.4. The exploit failed because the target lacked auto_login and a public flow identifier. The agent then broadened its reconnaissance to ten product families, searched GitHub for recent proof‑of‑concept code, and settled on n8n. It constructed the two‑vulnerability chain using CVE‑2026‑21858 and CVE‑2025‑68613, scanned the FOFA‑derived list of 25,209 n8n systems in China, sampled roughly 100, probed about 40, and located three vulnerable hosts. Despite the presence of exposed form endpoints, authentication requirements blocked successful exploitation, leading the agent to abandon the n8n track after determining that none of the surveyed systems met the full prerequisite set.

NetScaler Vulnerability Context
Citrix’s advisory clarifies that CVE‑2026‑3055 affects customer‑managed NetScaler ADC and Gateway appliances only when they are configured as SAML identity providers. The vulnerable code resides in the SAML profile handling component, where a memory‑overread can be triggered by malicious SAML responses. Administrators are urged to inspect their configurations for the directive add authentication samlIdPProfile .* and, if present, upgrade to the patched builds referenced in Citrix’s security bulletin. Applying the update eliminates the overread condition and prevents the data exfiltration observed in this campaign.

Attribution and Operator Location
Unit 42’s assessment places the threat actor’s operational base in Zhuhai, China. This conclusion draws from multiple open‑source indicators: the GitHub account associated with the aliases displays the name “KnYuan Knaithe,” and an archived blog under the same moniker describes its author as a binary security researcher residing in Zhuhai. While these details are consistent with the geographic attribution, they do not constitute proof of the operator’s legal identity, nor do they establish any direct linkage to a governmental or state‑sponsored entity. The analysis therefore treats the Zhuhai hypothesis as a plausible, albeit unverified, lead based on publicly available information.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here