Chinese Actor Uses Agentic AI for Autonomous Cyberattacks

Chinese Actor Uses Agentic AI for Autonomous Cyberattacks

While the autonomous agent conducted broad-spectrum scanning, the human operator concurrently managed to exfiltrate data from three organizations by exploiting specific vulnerabilities in Citrix NetScaler and Marimo instances. This dual-pronged offensive marks a pivotal moment in the evolution of cyber warfare, where the Chinese-speaking threat actor known as knaithe integrated the DeepSeek reasoning engine with the Hermes Agent framework. This integration transformed traditional manual hacking into a sophisticated, semi-autonomous operation capable of managing the entire offensive lifecycle with minimal human oversight. The campaign came to light through a rare stroke of luck for security researchers after the AI agent misconfigured a local server, effectively leaking its own operational logs. These logs provided an unprecedented window into how agentic AI can navigate complex digital environments, scout global infrastructure at machine speed, and execute strategic decisions that were once the exclusive domain of human intelligence analysts.

The Attack Lifecycle: Architectural Foundations of the Hermes Agent Framework

The operational backbone of this campaign centered on a Model Context Protocol server, which functioned as a sophisticated translator between high-level natural language instructions and granular technical execution. By leveraging this architecture, the attacker issued broad commands that the AI parsed into specific technical queries. The system then used search engines like FOFA to identify thousands of vulnerable targets across Chinese and Malaysian networks, specifically zeroing in on exposed VPN endpoints and workflow automation tools. Unlike the rigid scripts of the past, this agentic system displayed a remarkable level of cognitive flexibility, evaluating the potential value of a target based on its response patterns. If an initial exploit attempt encountered a robust security configuration or a generic error, the AI did not stall; instead, it autonomously categorized the system as low priority and pivoted its resources toward more promising targets.

Beyond simple target identification, the system demonstrated a terrifying ability to weaponize recent security research in real-time. The agent was programmed to monitor public platforms like GitHub for trending Proof-of-Concept exploits and technical disclosures. Once a high-severity vulnerability was identified, the Hermes framework could automatically download the code, modify it for the specific environment, and scan the internet for compatible endpoints. This process effectively reduced the time between a vulnerability’s public release and its widespread exploitation from days to mere hours. Such rapid weaponization places immense pressure on traditional defensive cycles, as the AI’s ability to assess and attack infrastructure operates at a scale that human defenders cannot match. By utilizing large language models as strategic decision-makers, the threat actor ensured that their offensive capabilities evolved as quickly as the defensive research they were designed to circumvent.

Hybrid Offensive Models: Integrating Precision With Autonomous Defense Strategies

While the autonomous agent provided the necessary scale to scan the global landscape, the human operator remained deeply involved in the final stages of high-stakes infiltration, particularly against low-code platforms like n8n and Langflow. This hybrid approach allowed the actor to maintain the relentless pace of a machine while applying the nuanced problem-solving skills of an expert hacker for the most sensitive tasks. Forensic analysis of the compromised environments revealed that the human behind the knaithe persona focused on sophisticated session hijacking techniques to move laterally within corporate networks. By stealing authentication cookies and manipulating session tokens, the attacker successfully bypassed multi-factor authentication protocols that would typically stop an automated bot. The focus on these automation tools, which are often deeply embedded but poorly patched, suggests a new standard for advanced persistent threats, where machine-led discovery is paired with human-led surgical precision to exploit sensitive business logic.

Looking back at the evolution of these incidents, security teams found it necessary to adopt monitoring techniques capable of identifying agentic behavioral signatures. They focused on detecting rapid-fire reconnaissance patterns and unusual bulk-version checking across internal infrastructure, which often signaled the presence of an automated scanner. Analysts also monitored for searches targeting public exploits that matched internal software versions, allowing them to anticipate attacks before they fully materialized. As threat actors refined their autonomous models and integrated custom skills to bypass AI safety filters, the defensive posture also transitioned toward a greater reliance on automated response mechanisms. The industry recognized that the only way to successfully combat offensive AI was through the deployment of defensive agents capable of acting with similar autonomy. These efforts successfully shifted the balance of power, ensuring that organizations remained resilient against the next generation of digital threats.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later