n8n GmbHHermes AgentCitrix Systems, Inc.DeepSeekUnit 42Langflow

Chinese hackers use DeepSeek and Hermes Agent to automate server exploits; Unit 42 tracks actor knaithe and KnYuan

Chinese hackers, identified as knaithe and KnYuan, are leveraging DeepSeek and Hermes Agent to automate server exploits, according to Unit 42. Their AI-assisted operations include reconnaissance and vulnerability research, targeting over 460 systems, although confirmed compromises remain unverified.

gbhackers.com gbhackers.com22 August 2026 · 08:55 UTC
CuriousCats Full Story

A Chinese-speaking threat actor has been observed using DeepSeek through the Hermes Agent framework to automate various stages of cyberattacks, including reconnaissance and exploit acquisition. This campaign, tracked by Unit 42 under the aliases knaithe and KnYuan, showcases the potential of AI-assisted offensive environments.12111213

The operation gained visibility when the Hermes Agent inadvertently launched a Python HTTP file server from the attacker’s home directory, exposing critical information such as tool configurations, API keys, and exploit scripts. The actor configured custom skills for LLM jailbreaking and WebSocket exploitation, integrating an MCP server to translate natural-language prompts into FOFA queries for asset discovery.34

In a notable incident from May 2026, the agent autonomously downloaded a public proof-of-concept exploit for the Langflow vulnerability, rated CVSS 9.8, identifying 84 exposed instances. However, exploitation failed due to the target's configuration. The actor also prioritized n8n workflow automation, identifying over 647,000 exposed instances globally.5678910

Despite the AI-directed campaigns not resulting in confirmed compromises, Unit 42 reported that the same actor successfully exfiltrated data from three organizations by exploiting the Citrix NetScaler vulnerability and achieved command execution on 11 Marimo notebook instances.

Key Insight
“The agent's accidental exposure of a Python HTTP file server revealed tool configurations, API keys, and attack logs. In May 2026, it targeted 84 exposed Langflow instances but failed due to missing auto_login; later pivoted to n8n, finding 647,000 exposed instances, though all required authentication.”
CuriousCats studied:
1
gbhackers.comgbhackers.com
“A Chinese-speaking threat actor has been observed using DeepSeek through the Hermes Agent framework to automate reconnaissance, vulnerability research, exploit acquisition, and attack attempts against internet-facing infrastructure.”
gbhackers.com →
Ask CuriousCats
What is DeepSeek used for?
Who is the threat actor knaithe?
Why did the attacks target n8n instances?
How does this breach compare to previous exploits?
Which tools are popular among hackers today?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
If you liked this, you’ll love your CuriousCats brief.
News, videos, opinions and more — without the noise.
Get CuriousCats