A Hacker Told DeepSeek to Attack the Internet, Then Walked Away

Chinese researchers linked DeepSeek to an open-source AI agent controlled via Telegram. Unit 42 found it could autonomously hunt for targets.
A Hacker Told DeepSeek to Attack the Internet, Then Walked Away
A hacker in China sent a single instruction over Telegram, then walked away. What happened next, according to security researchers, was an AI agent that spent the following hours picking its own targets, downloading its own exploit code, and attacking servers across the internet without another word from its operator. Palo Alto Networks' Unit 42 published the findings on July 30, and they describe something researchers had warned about for months but rarely caught in the wild: an AI model wired directly into an offensive hacking toolkit, running with minimal human oversight, end to end. What Unit 42 Actually Found The threat actor operates under the aliases "knaithe" and "KnYuan" and describes themself as a "binary security researcher." Unit 42 assesses the operator is based in China. The researchers only caught the campaign because of a basic mistake: the attacker's own AI agent, called Hermes, accidentally spun up a web server from its home directo…

About the author

Puneet Sharma is a freelance web developer, tech writer, and blogger. He is the founder of FWD Tools and runs WebDevPuneet and The Tech Watcher.

Post a Comment